1. Introduction
The anonymous company named COSMOTE Payments - ELECTRONIC MONEY SERVICES S.A., headquartered in Maroussi, Attica (99 Kifisias Ave.), (hereinafter referred to as COSMOTE Payments or the COMPANY) considers the protection of your personal data particularly important and adheres to the principle of transparency regarding its processing. If you wish to be generally informed about the processing of your personal data by COSMOTE Payments, please read the General Information on the Protection of Your Personal Data, which you can find here.
Through the Payzy by COSMOTE application (hereinafter the "Application"), various services are provided (hereinafter the "Services"), which are detailed in the respective text of the Terms and Conditions of use of the Application. A prerequisite for using the Application is the registration of the User in the Application for the provision of electronic money and payment services, which is provided by COSMOTE Payments and the identification of the user by them.
With this document, we wish to inform you about the processing of your personal data during the use of the Application and the Services.
These terms are part of the Terms and Conditions of Use of the Payzy by COSMOTE Application and should always be interpreted in conjunction with them and constitute a single set.
If the use of a Service provided through the Application is governed by separate terms regarding the processing of personal data, the latter are considered as one with these terms, but will prevail over them if they regulate the same issue differently.
2. What is the identity and contact information of the data controller?
The data controller is COSMOTE Payments, which you can contact via email at customerprivacy@cosmotepayments.gr or by postal mail to "COSMOTE Payments ELECTRONIC MONEY SERVICES SINGLE MEMBER S.A.," Maroussi, Attica (99 Kifisias Ave.).
3. Categories of Personal Data Collected and Processed During the Use of the Application and Services, and Their Purpose
3.1.1 For User Registration in the Application:
a. Email address and mobile phone number.
b. Full name, date and place of birth, home address, professional activity, tax data (TIN/Tax Office), identification document details (ID/passport), or
c. Taxisnet credentials to retrieve the data mentioned in b from the Digital Public Portal, along with documents verifying these details, such as the identification document (ID/passport), tax return (E1), and proof of profession and residence.
To achieve electronic remote identification of your details, COSMOTE Payments may process, with your consent, data such as:
- The recording of your visual and audio communication with our representative in real-time via video call.
- Biometric characteristics obtained from the recording of your dynamic selfie for verification against the photo in your identification document, using specialized software without the presence of our representative. If you do not consent to the use of biometric data, electronic remote identification will be conducted through a video call with a representative.
Read the text with which the relevant consent is provided here.
3.1.2 For transactions via the “Wallet” service (e.g., account loading/unloading [cash in/cash out], card transactions, balance display, and transaction history), the Application processes the following data:
- Information such as individual payment account number at COSMOTE Payments, bank account number (IBAN) at COSMOTE Payments and/or a third-party bank, transaction time, beneficiary, transaction amount, payment method.
- Payment card details for account loading/unloading.
- Payment card details for their use as a payment method within the Application.
3.1.3 For the use of the Chat & Pay Messaging Service and the transfer of electronic money from one User’s payment account to another’s (credit):
Data for the operation of Chat & Pay: Full name, email address, mobile phone number, profile picture, nickname, Payment Account Number (IBAN), User dialogues on COSMOTE Payments.
3.1.4 For participation in the Loyalty Program “Coins”:
The number of your personal debit card issued by COSMOTE Payments, payment history using the personal debit card issued by COSMOTE Payments, the number of reward points you have collected, reward point redemption history, payment account number (IBAN) at COSMOTE Payments.
3.1.5 For the use of the Split It Service (expense sharing):
- Data for participation in a Split It expense-sharing group: Full name, email address, mobile phone number, profile picture, nickname.
- Data for transaction settlement within a Split It expense-sharing group: Payment Account Number (IBAN) at COSMOTE Payments.
3.1.6 For the use of the Piggys Personal Safes Service:
Payment Account Number (IBAN) at COSMOTE Payments, my Vault Payment Account Number at COSMOTE Payments, the number of your personal debit card issued by COSMOTE Payments, payment history using the personal debit card issued by COSMOTE Payments.
3.1.7 For the issuance and use of cards via the Cards Service, specifically for applying for and issuing a payzy debit card (plastic or virtual):
ID details, postal address, Payment Account Number (IBAN) at COSMOTE Payments.
3.1.8 For bill payments using a unified RF payment code:
Payment Account Number (IBAN) at COSMOTE Payments, RF Payment Code details entered.
Additionally, for better service and resolving issues encountered during the use of the Services and Application, we process:
Data generated from your registration, activation, and use of the Services and Application, identity details, type, model, and characteristics of your device, connection details, communication with us (e.g., phone contact and availability, conversation recording with our representative, detailed problem description), transaction details, and other information shared with us for inquiry resolution, complaint handling, or charge disputes.
3.1.9 For transactions via the payzy pro Payment Service:
Full name, Payment Account Number (IBAN) at COSMOTE Payments, nickname.
3.1.10 Additionally, for reporting cashback rewards from payzy pro businesses, we process:
Payment Account Number (IBAN) at COSMOTE Payments, transaction date and time with cashback, cashback amount.
3.2 Based on Your Consent (Article 6(1)(a) of the GDPR), We Process Personal Data for the Following Purposes:
3.2.1 To inform you about which of your contacts hold a payment account at COSMOTE Payments:
Contact data on the terminal device where the Application is installed. If you have given consent, other users of the Application and holders of a Payment Account at COSMOTE Payments will be able to search for you to communicate via the Application. Depending on your preference, three alternative options allow other users of the Application to search for you. You can change your preference at any time in the Application settings under security settings -> who can search my profile?:
- Available for search by all Application users: All Application users and Payment Account holders at COSMOTE Payments can search for you by contact name, email, nickname, or mobile number provided during registration and identification at COSMOTE Payments.
- Available for search only by users of the Application who have saved the mobile number you provided during registration and identification at COSMOTE Payments in their terminal device contacts: Only users of the Application who have saved your mobile number in their contacts can search for you by contact name, email, nickname, or the mobile number provided during registration and identification at COSMOTE Payments.
- Not available for search: Your account remains hidden from all other users of the Application, and no one can search for you to communicate via the Application.
3.2.2 To display ratings for stores where you have made a payzy pro payment:
Nickname, profile picture, and store rating. The display of the rating on the payzy pro business page follows the user's preference described in 3.2.1. Specifically, if the user chooses to be available for search by all other users, the rating is visible to everyone. If the user chooses to be unavailable for search by anyone, the rating is not visible to anyone. If the user chooses to be available for search only by users who have saved their mobile number in their terminal device contacts, the rating is visible only to those users.
3.2.3 For participation in the “Invite Friends” promotion:
- Data for checking the eligibility for participation in the "Invite Friends" promotion: Full name, father’s name, mother’s name, ID details, account number, and status (IBAN) at COSMOTE Payments.
- Data resulting from participation in individual promotions: participation history, total reward amount, success details (e.g., the list of friends registering in the Application), account number, and balance (IBAN) at COSMOTE Payments.
3.2.4 Additionally, we process the following data to enhance your experience using the Application and the Services provided through it. Specifically:
To create a personal profile: Data generated from your registration, activation, and use of the Services and Application to create a personal profile based on your preferences. Creating a personal profile is a form of automated processing, through which we may assess your preferences, such as suggesting products that may interest you and sending related updates/advertisements tailored to your interests. You can disable this processing in the Application settings under terms of use and personal data -> personal profile and customization -> personal profile.
3.2.5 The Application provides the option to store your payment card (debit/credit/prepaid) so that it doesn’t need to be re-entered for each transaction. To protect payment card details and secure transactions, a tokenization process is applied to pseudonymize payment card numbers. Payment card details are stored in a secure environment at COSMOTE Payments.
3.3 Based on Our Legitimate Interest (Article 6(1)(f) of the GDPR), We Process Personal Data for the Following Purposes:
Receiving News and Updates: For the direct commercial promotion of our products and services, COSMOTE Payments may process a limited range of your data, mainly those contained in your contract, aggregate usage data, or requests submitted to us. This processing is limited to submitting proposals, offers, news, and updates about similar products and services. You have the right to object to communication from the Application settings under terms of use and personal data -> personal profile and customization -> news, updates, and promotional messages.
4. Trackers / Cookies
Cookies are small files stored on the user's computer or mobile device, placed by the websites they visit and/or the mobile applications they use, in order to recognize them. Beyond cookies, there are other trackers, such as pixels (e.g., Facebook Pixel), local storage, third-party SDKs included in mobile applications, etc. Trackers store information or access information stored on the user's terminal equipment (computer, mobile, tablet, etc.). Such trackers are used for the better functioning and improvement of Yzy Bot, accessing search data within Yzy Bot (questions, tags, keywords, etc.), and feedback data (e.g., navigation through service articles).
You can find out about the types of cookies / trackers we use and manage your options within the application, specifically from the settings menu → terms of use and personal data → manage trackers.
5. Application Permissions
The operation of the Application and the provision of Services through the Application require the installation and use of the Application, which depending on the operating system it is installed on, may require or request optional access to the following data on your terminal device:
- Contact Data: To inform you about which of your contacts are also Users of the Application and holders of a Payment Account with COSMOTE Payments.
- Location Data (GPS): To display your location on the map and inform you about offers in stores near you.
- Camera: To use the camera for setting your profile photo as well as the profile photo of the groups you create within the Application (e.g., for the "Split Bill" Service).
- Storage: Access is required to store PDFs of quarterly statements related to transactions and payment activities of your Payment Account, including those via Card analytics, your payment receipts, for alternative profile photo setting, and alternative group profile photo setting within the Application (e.g., for the "Split Bill" Service).
- Internet: The application requires internet access to communicate with COSMOTE Payments systems and display information relevant to you (e.g., login details, account information, etc.).
6. Display of Notifications (Push Notifications)
The application sends notifications to your device in order to:
- Notify you and/or complete transactions (e.g., for payment services),
- Alert you about messages received through the Chat & Pay Service,
- Send promotional messages and news, provided you have not opted out either during registration or through the settings in the "Communication Settings" section,
- Provide personalized suggestions and offers based on your individual profile, provided you have given your consent (in the "Communication Settings" section).
If you wish to opt out of receiving notifications altogether, you can change your options in your device's settings.
7. How long do we retain your personal data?
If you delete your account from the Application, your data (e.g., interactions with other Users, chat conversations) will be deleted in a way that makes it technically impossible to recover or anonymized, within 90 days.
8. Will COSMOTE Payments process your personal data for other purposes?
COSMOTE Payments will not process your personal data for purposes other than those mentioned above. If COSMOTE Payments wishes to use your personal data for other purposes, it will only do so after informing you and obtaining your explicit consent.
9. Who are the recipients of your personal data and for what purposes is it transferred?
Recipients of your personal data may include:
A. Third-party companies with which we cooperate for the provision and support of the Application and the Services provided through it. Specifically:
- Cognity SA, which supports the operation of the Application and is based in Greece.
- NEXI GREECE PROCESSING SERVICES SINGLE-MEMBER PRIVATE COMPANY, which provides payment processing and card issuing services and is based in Greece.
- NETCOMPANY-INTRASOFT S.A., which provides and supports the operation of COSMOTE Payments' banking systems and is based in Greece.
In these cases, these third-party companies are data processors on behalf of COSMOTE Payments, meaning they are partners of COSMOTE Payments who undertake a specific task following our instructions and applying the strict procedures of the OTE Group regarding the processing of your personal data. In these cases, COSMOTE Payments remains responsible for the processing of your personal data.
The processing of your personal data for the above purposes by our partners is mainly carried out within Greece and the European Union (EU). If we work with companies outside the EU, they will process your data only after our instructions and if there is an adequacy decision by the European Commission or if appropriate clauses are agreed upon to ensure a high level of security in relation to the processing of your personal data.
Beyond the aforementioned companies, COSMOTE Payments does not process or disclose your personal data to third parties except in cases where such disclosure/transmission is required by applicable law.
In the case of the processing purpose mentioned in 3.1.9 above, recipients of your personal data are:
The respective payzy pro business where you have made payments.
10. What are your rights as a user of the Service regarding the processing of your personal data?
The rights you can exercise include:
- Right of Access: You have the right to be informed about the personal data we process (e.g., the purposes of processing, types of data, recipients to whom it is disclosed, retention period) and to receive copies of this data.
- Right to Rectification: You have the right to request the correction of your data (e.g., correction of address, contact details).
- Right to Erasure: You have the right to request the deletion of your personal data if it is no longer necessary for the purposes for which it was processed or if you have withdrawn the consent on which the processing is based.
- Right to Restriction of Processing: You have the right to request the restriction of processing for a specific purpose (e.g., if you do not want to receive marketing updates via email).
- Right to Data Portability: You have the right to receive your personal data that you have provided to the company in a structured, commonly used, and machine-readable format.
- Right to Object: You have the right to object to the processing of your personal data in cases where you do not wish for your personal data to be processed.
To exercise your rights, you can:
a. Send an email to customerprivacy@cosmotepayments.gr, or
b. Fax to 2102511888, or
c. Mail a letter to Customer Service COSMOTE Payments, 99 Kifisias Avenue, 15124 Marousi, Greece with the subject "Exercise of Personal Data Rights"
accompanied by a copy of your ID and including your full name and the connection number of your mobile or landline phone.
If you believe that your request has not been sufficiently addressed and your personal data protection is affected in any way, you may submit a complaint through a dedicated online portal to the Hellenic Data Protection Authority (Athens, Kifisias Avenue 1-3, 115 23 | Tel: +30 210 6475600). Detailed instructions for submitting a complaint are provided on the Authority's website.
COSMOTE Payments will respond to your requests free of charge and without delay within one month of receiving the request. In exceptional cases, this period may be extended by two (2) months if required due to the complexity of your request. In any case, we will inform you of the extension and the reason for the delay.
If we consider that your request is manifestly unfounded or excessive, we reserve the right to charge a reasonable fee for its fulfillment, taking into account the administrative costs for its execution, or even to refuse to act on your request.
If you have any questions regarding the processing of your personal data by COSMOTE Payments or wish to exercise any of your rights, please refer to COSMOTE Payments' Data Protection Policy, which is available here.
11. What kind of measures are applied to protect your personal data?
At COSMOTE Payments, we implement appropriate technical and organizational measures in our corporate procedures, applying them to the information systems and platforms used for collecting, processing, or using data.
These measures include:
- Measures to prevent unauthorized access to data processing systems (access control).
- Measures ensuring that data processing systems cannot be used by unauthorized individuals (access denial).
- Measures ensuring that individuals authorized to use data processing systems have access only to the data they are authorized to use, and that personal data cannot be transmitted, copied, altered, or deleted by unauthorized persons during processing, use, or after recording (data access control).
- Measures ensuring that during electronic transmission, transfer, or recording, personal data cannot be transmitted, copied, altered, or removed by unauthorized individuals, and that it is possible to monitor and verify the processors to whom personal data has been transmitted via data transmission equipment (data transmission control).
- Measures ensuring that it is possible to retrospectively examine and verify whether and by whom personal data was entered, modified, or deleted in the data processing systems (data entry control).
- Measures ensuring that personal data processed by third parties/contractors is processed only according to our instructions (contractor control).
- Measures ensuring that data collected for different purposes can be processed separately (separation rule).