Retailrus Group Privacy Policy

Version 2.0 — January 2026
Applies to: Retailrus Ltd. and Trapyfy

1. Introduction

Retailrus Ltd. (“Retailrus,” “we,” “our,” or “us”) operates and manages the Trapyfy platform.

This Privacy Policy explains how we collect, use, disclose, store, and protect personal data in accordance with:

  • The EU General Data Protection Regulation (“GDPR”),
  • Applicable Maltese data protection law, and
  • Applicable legal obligations relating to financial crime prevention and platform security.

Where we process identity documents, screening results (e.g., sanctions/PEP), or other compliance-related data, we do so to support compliance, risk management, fraud prevention, and security controls applicable to the services we provide. The lawful bases for processing are described in Section 5.

By using any Retailrus-operated service, you acknowledge that you have read and understood this Privacy Policy.

2. Entities Covered and Data Protection Roles

This Privacy Policy applies to:

  • Retailrus Ltd. (Malta) — Parent entity and primary contracting entity for Retailrus-operated services.
  • Trapyfy — Merchant SaaS platform for e-commerce, point-of-sale services, and integrated payment compliance controls.

2.1 Default Controller/Processor Position

The data protection role depends on the specific service and purpose:

  • Account & Operations: Retailrus/Trapyfy acts as a data controller for merchant account administration, billing, service operations, and security logging.
  • Merchant Customer Data: Where Trapyfy processes end-customer data on behalf of a merchant (e.g., orders/customer details entered by the merchant), Trapyfy acts as a processor for that merchant, subject to a written Data Processing Agreement (DPA).
  • Compliance & Payments: Trapyfy acts as a data controller for KYC/KYB, screening, investigations, audit logging, and transaction execution metadata processed for compliance and platform integrity purposes.

3. Personal Data We Collect

3.1 Trapyfy Merchant & Service Data

  • Merchant registration and account details
  • Business contact information
  • Billing and subscription data
  • Product listings, orders, and platform event logs
  • Customer support and communication records

3.2 Trapyfy Compliance & Payment Data

  • Merchant (and associated persons) KYC/KYB information
  • Verified identity attributes and ownership/control data
  • Wallet addresses and payment-related metadata
  • Transaction execution metadata, including routing events and blockchain references
  • Screening and monitoring outputs (risk indicators, sanctions screening, PEP classifications)

3.3 Common Technical Data

  • Device, browser, and usage information
  • Website analytics and cookies
  • Communication preferences and support tickets

4. How We Use Personal Data

We process personal data to:

  • Provide, operate, and maintain our services;
  • Administer accounts and support users and merchants;
  • Verify identities where required for onboarding and risk controls;
  • Detect and prevent fraud, sanctions breaches, or unauthorized activity;
  • Maintain platform security, logging, and auditability;
  • Comply with lawful requests and applicable legal, regulatory, and audit requirements.

5. Lawful Bases for Processing (GDPR)

We rely on the following lawful bases:

  • Contract performance — To provide requested services and support.
  • Legal obligation — Where processing is required by law (e.g., AML/KYC).
  • Legitimate interests — To protect platform security and prevent fraud.
  • Consent — For marketing and non-essential cookies.

6. Data Sharing and Disclosure

We share personal data only where necessary, including:

  • Intragroup: Between Retailrus and Trapyfy departments for service delivery and risk management.
  • External Partners: Identity verification providers, cloud hosting (infrastructure), blockchain analytics vendors, and banking/settlement partners.
  • Legal Authorities: Regulators and law enforcement where legally required.

Retailrus does not sell personal data.

7. International Data Transfers

Personal data is primarily stored within the European Union. Where transfers outside the EEA occur, we implement safeguards such as Standard Contractual Clauses (SCCs) and Transfer Impact Assessments (TIAs).

8. Data Retention and Security

Retention

Compliance records are generally retained for seven (7) years following the end of the business relationship. Other data is retained only as long as necessary for its specific purpose.

Security Measures

  • Encryption at rest and in transit;
  • Role-based access controls and multi-factor authentication;
  • Regular security assessments and auditable logging.

9. Your Rights Under GDPR

Subject to legal limitations, you may request to access, correct, delete, or restrict your data. You also have the right to data portability and to object to processing. Where compliance obligations apply, certain data may be retained despite deletion requests.

10. Automated Decision-Making

Automated systems may support identity verification and screening. Material decisions (like account rejection) are subject to human review and MLRO oversight.

11. Cookies and Tracking

We use cookies to improve our services. Please refer to our separate Cookie Policy for full details.

12. Children’s Data

Trapyfy services are intended for adults (18+). We do not knowingly collect personal data from minors.

13. Policy Updates

This policy is reviewed periodically. Material updates will be published here with a revised effective date.

14. Contact Information

Retailrus Ltd.
Centris Business Gateway, Level 4/W
Central Business District, Birkirkara, Malta
Email: [email protected]


Version Control

Version Date Description Approved By
1.0 Nov 10 2025 Initial release covering Retailrus & Trapyfy MLRO / Compliance Committee
1.1 Dec 17 2025 Updates to clarify language MLRO / Compliance Committee
2.0 Jan 8, 2026 Alignment to data retention and updated definitions MLRO / Compliance Committee