Version 2.0
Effective date: September 1, 2026
The CardsPro technology platform and the associated intellectual property are owned by Kaizo FZE LLC., a company incorporated under the laws of the United Arab Emirates, with its registered office at BC-892957, Amber Gem Tower, Ajman (the "System Owner").
CardsPro is a technology platform and is not a bank, deposit-taking institution, electronic money institution, payment institution, card issuer, card network or other financial institution. Card issuance, payment processing, safeguarding, settlement and other regulated financial or payment services are provided by independent licensed or otherwise duly authorised third-party partners under their own terms, regulatory permissions and acceptance criteria.
This Privacy Policy explains how the System Owner collects, uses, stores, discloses and protects personal data in connection with the CardsPro website, dashboard, API, white-label interfaces, onboarding, support, security tools and other technology services.
This Policy is intended to address the requirements of the EU General Data Protection Regulation (“GDPR”), the UK GDPR and other applicable data-protection laws, in each case only to the extent that the relevant law applies to a particular processing activity.
This Policy applies to website visitors, prospective and current Clients, Authorised Users, End Users, cardholders, beneficial owners, directors, officers, employees, contractors, Partner representatives, contacts and other individuals whose personal data is processed in connection with CardsPro.
This Policy does not replace a Partner’s own privacy notice. Independent licensed or authorised Partners may process personal data for card issuance, payment processing, safeguarding, settlement, sanctions compliance, fraud prevention and other regulated purposes under their own legal responsibilities.
The owner of the CardsPro technology platform and the entity responsible for the processing activities described in this Policy, where it determines the purposes and means of processing, is:
Kaizo FZE LLC.
Registered office: UAE, BC-892957, Amber Gem Tower, Ajman.
Privacy and general contact: contacts.
In this Policy, “CardsPro”, “System Owner”, “we”, “us” and “our” refer to Kaizo FZE LLC., unless the context indicates otherwise.
CardsPro provides technology and operational tools. It does not, solely by operating the platform, act as a bank, card issuer, payment institution, electronic-money institution or deposit-taking institution.
Partners may independently determine why and how personal data must be processed to satisfy financial-services laws, card-network rules, customer due diligence, transaction authorisation, settlement, safeguarding, dispute handling and regulatory reporting requirements. Depending on the activity, a Partner may act as an independent controller, joint controller or processor.
Where practicable, the applicable product flow, Partner terms or Partner privacy notice will identify the relevant regulated provider. A request relating exclusively to a Partner’s independent processing may be referred to that Partner.
The System Owner generally acts as a controller for data collected for website operation, Client onboarding, account administration, security, fraud prevention, direct support, service improvement, billing, marketing and its own legal or compliance obligations.
Where the System Owner processes personal data solely on documented instructions from a Client under an API or white-label arrangement, the Client generally acts as controller and the System Owner acts as processor or sub-processor. The applicable Data Processing Agreement governs that processing.
The role allocation depends on the actual purpose and decision-making authority, not merely on the terminology used in a contract. Each Client remains responsible for determining its own role, providing legally required notices and establishing a lawful basis for data it submits.
Depending on the relationship and enabled functionality, we may process the following categories:
We do not intentionally request passwords, complete card security codes or other authentication secrets through support channels. Individuals should not submit information that is unnecessary for the request.
We may obtain personal data:
Where data is obtained from another organisation, that organisation is responsible for having lawful authority to disclose it. We will provide any additional notice required by applicable law unless an exemption applies.
We process personal data only where a lawful basis applies. The applicable basis depends on the purpose and jurisdiction.
Partner rules and contractual requirements do not automatically constitute a legal obligation under the GDPR. Where no statutory obligation applies directly to the System Owner, processing will rely on another valid basis, such as contract performance or legitimate interests.
Personal data may be processed to:
We do not sell personal data in exchange for money. If a jurisdiction defines “sale” or “sharing” more broadly, any applicable opt-out mechanism will be provided as required.
The System Owner and Partners may combine identity, business, device, transaction and public-source information to assess financial-crime, fraud, sanctions, cybersecurity and operational risk.
Monitoring may identify unusual transaction frequency or value, inconsistent locations, repeated declines, refunds, chargebacks, blocked-card use, suspicious API behaviour, account links, high-risk merchants or activity inconsistent with the stated business model.
Data may be retained and disclosed where necessary to investigate suspicious activity, protect users and Partners, comply with law or establish and defend claims. We may be legally or contractually restricted from disclosing specific monitoring rules, reports or investigation details.
We do not seek special-category data unless it is necessary and legally permitted. Identity documents, photographs, selfies and liveness checks may reveal sensitive information. Facial images become biometric data under the GDPR when technically processed for the purpose of uniquely identifying a person.
Where biometric or other special-category processing occurs, we will identify an appropriate condition under applicable law. Depending on the circumstances, this may include explicit consent, substantial public interest established by law, prevention of fraud, or the establishment, exercise or defence of legal claims.
Third-party identity-verification providers may independently determine technical verification methods and retention periods. Their applicable privacy notices should be reviewed before verification is completed.
Automated rules may be used for sanctions screening, identity verification, fraud detection, transaction monitoring, security alerts, risk scoring and routing cases for manual review.
Automated outputs may result in a transaction delay, request for further information, reduced limit, temporary restriction or referral to a Partner. Where Article 22 GDPR or an equivalent rule applies to a decision based solely on automated processing that produces legal or similarly significant effects, we will rely on a permitted legal basis and provide applicable safeguards, which may include human intervention, an opportunity to express a view and a right to contest the decision.
These rights do not require disclosure of information that would undermine fraud prevention, security, sanctions controls, trade secrets or a confidential investigation.
We may disclose personal data, subject to necessity and applicable safeguards, to:
Recipients receive only the data reasonably necessary for the relevant purpose. Service providers acting on our behalf are subject to contractual data-protection and confidentiality obligations appropriate to their role.
CardsPro and its Partners operate internationally. Personal data may therefore be transferred to or accessed from jurisdictions outside the UAE, European Economic Area or United Kingdom.
Where required, we use an applicable transfer mechanism, which may include an adequacy decision, European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, contractual safeguards under UAE law, binding corporate rules, certification or a legally permitted derogation for a specific transfer.
Where appropriate, we assess the destination country and supplementary technical, contractual or organisational measures. Information about the relevant safeguard may be requested through contacts, subject to protection of confidential information.
Personal data is retained only for as long as reasonably necessary for the purpose for which it was collected and for applicable legal, contractual, audit, security and dispute-resolution requirements.
Retention is determined by reference to:
Marketing data is retained until opt-out, withdrawal of consent or expiry of the applicable campaign period, while limited suppression records may be retained to honour an opt-out. Consent records may be retained to demonstrate compliance. Backup copies are deleted or overwritten according to secure backup cycles unless preservation is legally required.
When retention is no longer necessary, data is securely deleted or irreversibly anonymised.
We maintain technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include access controls, multi-factor authentication, encryption, segregation of duties, logging, monitoring, secure development, vulnerability management, vendor due diligence, staff training, backups and incident-response procedures.
No system can be guaranteed completely secure. Individuals and Clients must protect credentials, use secure devices and promptly report suspected compromise. Security reports may be submitted through contacts.
Where a personal-data breach occurs, we will assess its nature and risk and notify affected controllers, supervisory authorities or individuals where and within the period required by applicable law.
We may send business and product communications where permitted on the basis of consent or legitimate interests. Marketing messages will identify an available unsubscribe or opt-out method.
Withdrawing marketing consent does not stop service, security, compliance, billing or contractual communications. We may retain minimal contact information on a suppression list to ensure that the opt-out is respected.
Subject to applicable law, exemptions and verification, an individual may have the right to:
These rights are not absolute. A request may be limited or refused where data must be retained for law, sanctions, AML/CFT, fraud prevention, security, legal claims, card-network obligations or the rights of another person. We will explain the applicable reason unless prohibited from doing so.
Requests may be submitted through contacts. The request should describe the right being exercised and provide sufficient information to identify the relevant account or relationship. Individuals should not send passwords, full card security codes or unnecessary identity documents.
Where we have reasonable doubts about identity or authority, we may request additional information limited to what is necessary to prevent unauthorised disclosure. An authorised representative may be required to provide evidence of authority.
Where the GDPR applies, we will respond without undue delay and generally within one month after receiving a complete request. The period may be extended by two additional months where permitted due to complexity or volume, and we will provide notice of the extension. Requests are generally free, subject to lawful exceptions for manifestly unfounded or excessive requests.
Where we process data solely for a Client as processor, we may refer the request to that Client and assist it in responding under the Data Processing Agreement.
Privacy complaints may be submitted through contacts. We will investigate and respond in accordance with applicable law.
Where the GDPR applies, an individual may complain to a supervisory authority in the EU or EEA country of habitual residence, place of work or alleged infringement. Where the UK GDPR applies, a complaint may be made to the UK Information Commissioner’s Office. Rights available under UAE law may be exercised before the competent UAE authority or court as applicable.
Contacting us first is encouraged but is not a prerequisite to filing a complaint with a competent authority.
We use cookies and similar technologies for operation, security, preference storage, analytics and, where enabled, marketing. Non-essential technologies are used on the basis of consent where required. Further information is contained in the CardsPro Cookie / Tracking Policy and the live cookie preference centre.
CardsPro is intended exclusively for corporate users and adults acting in a professional or business capacity. The Service is not directed or offered to persons under 18, who may not register, undergo verification or use the Service. Parental or guardian consent does not override this eligibility restriction.
We do not knowingly request or collect a minor’s personal data to create an account or provide the Service directly to that minor, and we do not knowingly use such data for direct marketing, behavioural advertising or commercial profiling.
We may apply proportionate age-assurance measures where justified, while limiting processing to information reasonably necessary to confirm eligibility.
In limited circumstances, data concerning a minor may be received from a Client, Partner or third party, for example in lawful beneficial-ownership documentation. Such data is processed only where necessary, supported by an appropriate legal basis and subject to enhanced safeguards.
If we learn that a minor’s data was submitted contrary to this Policy, we will take reasonable steps to stop the unauthorised processing and delete or anonymise the data without undue delay, unless retention is required or permitted for compliance, fraud prevention, security or legal claims. A parent or legal representative may contact us through contacts.
Personal data may be disclosed or transferred in connection with a merger, acquisition, financing, restructuring, insolvency or sale of all or part of the CardsPro business or assets. We will apply confidentiality and lawful-transfer safeguards and provide any notice required by applicable law.
We may update this Policy to reflect changes in the Service, processing activities, Partners, technologies, security practices or legal requirements. Each version will state its effective date.
The current version will be published on the CardsPro website or made available through the Service. For material changes affecting data categories, purposes, legal bases, recipients, international transfers, retention, automated decision-making or individual rights, we will provide reasonable advance notice by email, dashboard notice, website banner or another appropriate method where practicable.
Where we intend to process personal data for a new purpose, we will provide required information before that processing and establish a valid legal basis. Where consent is required, continued use of the Service will not by itself constitute consent.
Immediate updates may be made where necessary to comply with law, address an urgent security issue or prevent fraud or harm.
Data controller / System Owner: Kaizo FZE LLC.
Registered office: Geneva Place, UAE, BC-892957, Amber Gem Tower, Ajman.
Privacy questions, requests and complaints: contacts.
Please provide sufficient information to understand and locate the relevant data, but do not submit unnecessary passwords, complete card details, private keys or other sensitive credentials.