Pixxles Ltd
Privacy Policy
Last updated: June 2026
1. Introduction
Pixxles Ltd (“Pixxles”, “we”, “us”, “our”) is a UK-registered company providing payment acquiring, compliance, and related financial technology services. We are committed to protecting your personal data and handling it transparently, securely, and in accordance with applicable data protection law, including:
- The UK General Data Protection Regulation (UK GDPR)
- The Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025)
- The Privacy and Electronic Communications Regulations 2003 (PECR)
- The Payment Services Regulations 2017 (PSRs)
- The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs)
This Privacy Policy explains how we collect, use, store, and share personal data when you:
- Visit our website
- Apply for or use our payment services
- Make a payment to one of our merchants (as a cardholder or end customer)
- Communicate with us (including by email, phone, or SMS)
- Act as a representative of one of our customers, partners, or suppliers
- Apply for employment with us
This policy does not cover personal data processed by our merchants. When you make a payment to a merchant using our acquiring services, the merchant is a separate data controller and has its own privacy policy governing its use of your data.
2. Data Controller
Pixxles Ltd is the data controller for the personal data described in this Privacy Policy.
| Field | Detail |
| Company name | Pixxles Ltd |
| Company number | 11604773 |
| Registered address | 78 Cannon Street, London, EC4N 6AF, United Kingdom |
| FCA authorisation | Authorised Electronic Money Institution, FRN 927960 |
| General enquiries | [email protected] |
| Data protection enquiries | [email protected] |
| Data Protection Lead | Zed Eagling-Rana, Head of Compliance |
| Complaints | [email protected] |
3. Who This Policy Applies To
We process personal data relating to several categories of individuals, depending on their relationship with us:
- Merchants and their representatives: individuals who apply for or use our acquiring services, including company directors, authorised signatories, and beneficial owners
- Cardholders and end customers: individuals who make payments to merchants using our acquiring platform. We process limited transaction data in connection with payment processing.
- Website visitors: individuals who visit our website
- Employees and contractors: our staff and workers (covered in more detail in our Staff Privacy Notice)
- Job applicants: individuals who apply for roles with us
- Suppliers and partners: representatives of companies we work with
- Complainants: individuals who submit complaints to us, including data protection complaints
4. Categories of Personal Data We Collect
4.1 Data you provide to us
- Identity and contact data: name, job title, company name, email address, telephone number, postal address
- Account and application data: information provided in onboarding forms, including business details, bank account information, and identification documents
- Due diligence data: information collected for anti-money laundering (AML), know-your-customer (KYC), and sanctions screening purposes, including identity verification documents, proof of address, and beneficial ownership information
- Communications data: emails, calls, SMS messages, and other correspondence with us
- Complaint data: information provided when submitting a complaint, including data protection complaints under s.164A DPA 2018
4.2 Data we collect automatically
- Technical data: IP address, device type, browser information, operating system
- Usage data: pages visited, time spent on our website, referring URLs
- Cookie data: see Section 14 (Cookies) below
4.3 Data we receive from third parties
We may receive personal data from sources other than the data subject, including:
- Card networks: Visa, Mastercard, and other card schemes provide transaction data (including cardholder name, card number, and transaction details) in connection with payment processing
- Sponsor banks and payment partners: settlement, chargeback, and dispute information
- Fraud prevention and screening services: risk scores, fraud alerts, and screening results
- Credit reference and identity verification agencies: identity verification results and creditworthiness information for merchant onboarding
- Companies House and public registers: company and director information for due diligence. This data comes from publicly accessible sources.
- Regulators: information received from the FCA, ICO, HMRC, or law enforcement in connection with regulatory enquiries
Where we process personal data that we have not collected directly from you, we will inform you of the source and the categories of data within a reasonable period, and no later than one month, unless an exemption applies (for example, where disclosure would prejudice a criminal investigation).
5. How and Why We Use Your Personal Data
We only process personal data where we have a valid lawful basis under Article 6 UK GDPR.
| Purpose | Data used | Lawful basis |
| Providing and administering our acquiring services | Identity, contact, account, transaction data | Performance of a contract (Art 6(1)(b)) |
| Processing payments on behalf of merchants | Cardholder name, card details, transaction data | Legitimate interests (Art 6(1)(f)) in providing payment processing services to our merchants |
| AML/KYC screening and sanctions checks | Identity, due diligence, screening data | Legal obligation (Art 6(1)(c)) under the MLRs 2017, PSRs 2017, and Proceeds of Crime Act 2002 |
| Fraud prevention and transaction monitoring | Transaction, technical, screening data | Legitimate interests (Art 6(1)(f)) in preventing fraud and financial crime; also legal obligation under PSRs 2017 |
| Responding to enquiries and providing support | Contact, communications data | Legitimate interests (Art 6(1)(f)) in providing customer service |
| Handling complaints (FCA and data protection) | Identity, contact, complaint data | Legal obligation (Art 6(1)(c)) under DISP, PSRs, and s.164A DPA 2018 |
| Regulatory reporting to the FCA and ICO | Complaint, transaction, compliance data | Legal obligation (Art 6(1)(c)) |
| Improving our website and services | Technical, usage data | Legitimate interests (Art 6(1)(f)) in service improvement |
| Sending service-related communications (including SMS) | Contact data | Performance of a contract or legitimate interests |
| Sending marketing communications | Contact data | Consent (PECR and Art 6(1)(a) UK GDPR) |
| Recruitment and job applications | Identity, contact, CV/application data | Legitimate interests (Art 6(1)(f)) in assessing candidates; consent where required |
Where we rely on legitimate interests, we have carried out a balancing test to ensure our interests are not overridden by your rights and freedoms. You can request details of these assessments by contacting [email protected].
5.1 Is providing your personal data a requirement?
In some cases, providing your personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract with us:
- Merchant onboarding: providing identity, due diligence, and business information is a contractual requirement to use our acquiring services, and a statutory requirement under the Money Laundering Regulations 2017. If you do not provide this data, we will be unable to offer you our services.
- AML/KYC screening: providing identity verification information is a legal obligation. If you do not provide this data, we are required by law to decline or terminate the business relationship.
- Transaction processing: cardholder data is provided by the card networks as a necessary part of processing payments. This data is essential for the performance of the payment service.
- Website and marketing: providing your contact details for marketing is voluntary and based on consent. You are not required to provide this data, and there are no consequences for choosing not to.
6. Special Category Data
We do not routinely collect or process special category data (such as data about racial or ethnic origin, political opinions, religious beliefs, health, sex life, or biometric data) in connection with our acquiring services.
In limited circumstances, we may process special category data in connection with:
- Employee health records for absence management and statutory sick pay (legal obligation and employment law)
- Reasonable adjustments for individuals with disabilities in the context of complaints handling or service provision (substantial public interest under Schedule 1 DPA 2018)
Where we process special category data, we do so only with an appropriate lawful basis under Article 9 UK GDPR and a relevant condition under Schedule 1 of the DPA 2018.
7. Marketing Communications
We may send you marketing communications about our services only where permitted by law.
- Email and SMS marketing: we will only send marketing messages where you have given your consent or where another PECR exemption applies (such as the soft opt-in for existing customers).
- You can withdraw your consent at any time by using the unsubscribe link in an email, replying “STOP” to an SMS, or contacting us.
- Withdrawing consent will not affect the lawfulness of any processing carried out before withdrawal.
We do not share your contact details with third parties for their own marketing purposes.
8. SMS Participation Requirements
Our SMS communications are intended for adults and business users. To participate in receiving SMS messages from Pixxles:
- You must be 18 years of age or older
- You must be the owner or authorised user of the mobile telephone number provided
- Your device must be capable of receiving SMS messages
Standard message and data rates may apply, depending on your mobile network and tariff.
9. Who We Share Personal Data With
We may share personal data with the following categories of recipients where necessary:
- Card networks: Visa, Mastercard, and other card schemes for payment processing, chargebacks, and dispute resolution
- Sponsor banks and payment partners: for settlement, transaction processing, and regulatory compliance
- Cloud hosting and technology providers: for secure storage and processing of data
- Fraud prevention services: for transaction screening, risk scoring, and fraud detection
- AML and identity verification providers: for KYC checks, sanctions screening, and ongoing monitoring
- SMS and communications providers: for service and marketing communications
- Professional advisers: legal, compliance, audit, and accounting advisers
- Regulators and authorities: the FCA, ICO, HMRC, law enforcement, and other regulatory bodies where required by law or in response to a lawful request
All third parties act as data processors or independent controllers and are subject to appropriate contractual and security obligations, including data processing agreements where required.
We do not sell personal data. We do not share SMS opt-in data or consent records with third parties for their own purposes.
10. International Transfers
Some of our service providers may be located outside the UK. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including:
- UK International Data Transfer Agreements (IDTAs)
- UK Addendum to EU Standard Contractual Clauses
- Transfers to countries recognised by the UK as providing adequate protection for personal data
You can request information about the safeguards we use for international transfers by contacting [email protected].
11. Data Security
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it, including:
- PCI DSS compliance for the handling of cardholder data
- Encryption of data in transit and at rest
- Access controls and role-based permissions
- Regular security testing and vulnerability assessments
- Staff training on data protection and information security
- Incident response and data breach management procedures
While we take all reasonable steps to protect your data, no method of transmission over the internet or electronic storage is completely secure. If you have reason to believe that your data may have been compromised, please contact us immediately at [email protected].
12. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including to meet legal, regulatory, and accounting requirements.
| Data category | Retention period | Basis |
| Merchant account and application data | 6 years after end of relationship | FCA record-keeping; Limitation Act 1980 |
| AML/KYC due diligence records | 5 years after end of business relationship | MLRs 2017 Reg 40 |
| Transaction and payment data | 6 years from transaction date | PSRs 2017; tax and accounting requirements |
| Cardholder data (card numbers) | As required for processing; then securely deleted per PCI DSS | PCI DSS; data minimisation |
| FCA complaints records | 3 years minimum from date of complaint; 6 years where redress paid | DISP 1.9 |
| Data protection complaints records | 3 years minimum from date of complaint | s.164A DPA 2018; ICO accountability |
| Communications (email, calls, SMS) | 6 years | Regulatory record-keeping |
| Marketing consent records | Duration of consent plus 2 years | PECR; accountability |
| Job application data (unsuccessful) | 6 months after decision | Legitimate interests; Equality Act limitation |
| Website analytics and cookie data | Up to 13 months | PECR; data minimisation |
Data is securely deleted or anonymised when no longer required.
13. Automated Decision-Making and Profiling
In connection with our acquiring services, we use automated systems for:
- Transaction risk scoring: automated fraud screening tools may assign a risk score to transactions to help identify potentially fraudulent activity. High-risk transactions may be flagged for manual review or declined.
- AML/sanctions screening: automated screening tools check merchant applicants and beneficial owners against sanctions lists and politically exposed persons (PEP) databases.
These automated processes may produce decisions that affect whether a transaction is processed or whether a merchant application is approved. Where a decision is made solely by automated means and has a significant effect on you, you have the right to:
- Request human review of the decision
- Express your point of view
- Contest the decision
To exercise these rights, contact [email protected]. Pixxles will ensure a qualified person reviews the decision and communicates the outcome to you.
14. Cookies
We use cookies and similar technologies on our website. Cookies are small text files placed on your device that help us understand how you use our site and improve your experience.
We use the following types of cookies:
- Strictly necessary cookies: required for the website to function. These do not require consent.
- Analytics cookies: help us understand how visitors interact with our website. We use these to improve our site. Under the Data (Use and Access) Act 2025 amendments to PECR, certain analytics cookies may be placed without consent where they are used only for statistical purposes and an opt-out is provided.
- Marketing cookies: used to deliver relevant advertisements. These require your consent before being placed.
You can manage your cookie preferences through your browser settings or through the cookie consent tool on our website. Further information is available in our Cookie Policy.
15. Children
Our services are not directed at children under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will take steps to delete it as soon as possible.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us at [email protected].
16. Your Rights
Under UK GDPR, you have the following rights in relation to your personal data:
- Right of access: to request a copy of the personal data we hold about you
- Right to rectification: to request correction of inaccurate or incomplete data
- Right to erasure: to request deletion of your data in certain circumstances
- Right to restrict processing: to request that we limit how we use your data
- Right to data portability: to request your data in a structured, machine-readable format
- Right to object: to object to processing based on legitimate interests or for direct marketing. If you object to processing for direct marketing, we will stop immediately. If you object to processing based on legitimate interests, we will stop unless we can demonstrate compelling grounds that override your interests.
- Right to withdraw consent: where processing is based on consent, you can withdraw at any time. This will not affect the lawfulness of processing before withdrawal.
- Rights relating to automated decision-making: see Section 13 above
To exercise any of these rights, contact [email protected] or write to Data Protection Lead, Pixxles Limited, 78 Cannon Street, London, EC4N 6AF. We will respond within one month. There is no fee, although we may charge a reasonable fee for manifestly unfounded or excessive requests.
16.1 Your right to make a data protection complaint to Pixxles
Under section 164A of the Data Protection Act 2018, you have the right to make a complaint directly to us if you believe we have handled your personal data in a way that infringes data protection law. You do not need to use any specific form or legal language.
You can submit a data protection complaint in any of the following ways:
- Email: [email protected]
- Phone: +44 208 126 4154 (UK business hours)
- Post: Complaints Handling Team, Pixxles Limited, 78 Cannon Street, London, EC4N 6AF
We will acknowledge your complaint within 30 days of receiving it. We will then investigate and let you know the outcome without undue delay, keeping you informed of progress. All data protection complaints are handled by our Data Protection Lead.
16.2 Your right to complain to the ICO
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent supervisory authority for data protection. The ICO generally expects you to raise your concern with us first so that we have the opportunity to resolve it directly.
Information Commissioner’s Office
- Website: https://www.ico.org.uk
- Telephone: 0303 123 1113
- Live chat: available via the ICO website
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
17. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be available on our website, and material changes will be communicated where required. We encourage you to review this policy periodically.
18. Contact Us
If you have any questions about this Privacy Policy or how we use your personal data:
| Contact | Details |
| General enquiries | [email protected] |
| Data protection enquiries | [email protected] |
| Complaints (including DP complaints) | [email protected] |
| Postal address | Pixxles Limited, 78 Cannon Street, London, EC4N 6AF |
| Phone | +44 208 126 4154 |

