This Privacy Policy explains how Kuentoo B.V. collects, uses, shares and protects personal data in connection with the website at kuentoo.com and the services we provide. We take the protection of personal data seriously and process it only as described here and as the law requires of a payment provider.
Kuentoo B.V. — data controller
Kaya C.E.B. Hellmund 6, Kralendijk, Bonaire, Caribbean Netherlands
E-mail: info@kuentoo.com
On this page
1. Who is responsible
Kuentoo B.V. is the controller for the personal data described in this policy. For merchant onboarding and payment processing, we act both as a controller (for our own compliance, risk and accounting obligations) and, where applicable, as a processor on behalf of our merchants for their customers' transaction data.
2. Scope
This policy covers personal data we process about: visitors to our Website; people who contact us or request information; representatives of businesses that apply to become or are Kuentoo merchants; and, in a limited way, the customers who make payments to those merchants through our infrastructure.
3. Data we collect
Website visitors and enquiries
- contact details you provide (name, business name, e-mail, phone, message);
- technical data such as IP address, device and browser type, and pages viewed, collected through server logs and cookies;
Merchant onboarding (KYC)
- business details: legal name, trade name, registration number, address, website and business activity;
- details of directors and ultimate beneficial owners, including identity document data, needed to meet know-your-customer and anti-money-laundering obligations;
- bank account and settlement details;
- expected and actual transaction volumes.
Payment processing
- transaction data such as amount, currency, date, reference and outcome. Full card numbers are handled within PCI-DSS certified payment systems; Kuentoo does not store complete card details on its own servers.
4. Why we use it
We process personal data to: respond to enquiries and provide information; assess and onboard merchants; provide, operate and support our payment services; meet legal obligations, including anti-money-laundering, sanctions, tax and financial-supervision requirements; prevent and detect fraud and abuse; keep our systems secure; and maintain our records. We rely on the legal bases of performance of a contract, compliance with a legal obligation, our legitimate interests in running and securing our business, and, where required, your consent.
5. Cookies and analytics
Our Website uses a small number of cookies and similar technologies that are necessary for the site to function and to keep it secure. We may also use limited analytics to understand how the Website is used and improve it. The Website loads web fonts from Google Fonts and is served through a content-delivery and security network, which process technical data such as your IP address to deliver and protect the pages. You can control cookies through your browser settings; disabling necessary cookies may affect how the Website works.
6. Who we share it with
We share personal data only where necessary, with:
- regulated payment processing partners, acquiring banks and card networks that execute and settle transactions;
- identity-verification, fraud-prevention and compliance service providers;
- IT, hosting, cloud and communications providers that operate our systems on our behalf under confidentiality and data-processing terms;
- professional advisers, auditors and, where legally required, regulators, supervisory authorities and law-enforcement bodies.
We do not sell personal data.
7. International transfers
Some of our providers process data outside Bonaire and the Caribbean Netherlands, including in the European Union and the United States. Where personal data is transferred across borders, we take appropriate steps to ensure it remains protected in accordance with applicable law.
8. How long we keep it
We keep personal data only as long as needed for the purposes above. Merchant and transaction records subject to anti-money-laundering, financial and tax rules are retained for the periods those rules require (commonly several years after the relationship ends). Enquiry and website data is kept for a shorter period.
9. How we protect it
We apply technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit, access controls, two-factor authentication for account access, and the use of PCI-DSS certified systems for card data. No system is completely secure, but we work to protect personal data against loss, misuse and unauthorised access.
10. Your rights
Subject to applicable law, you may ask us to: access the personal data we hold about you; correct data that is inaccurate; delete data where we no longer need it; restrict or object to certain processing; and receive certain data in a portable form. To exercise a right, contact us using the details below. We may need to verify your identity before acting, and some data must be retained where the law requires it.
11. Children
Our Website and services are intended for businesses and adults. We do not knowingly collect personal data from children.
12. Changes
We may update this policy from time to time. The version published on this page, with the "Last updated" date above, is the current version. Material changes will be made clear on this page.
13. Contact and complaints
For any question about this policy or to exercise your rights, contact info@kuentoo.com. If you believe we have not handled your personal data properly, you may also lodge a complaint with the competent data-protection supervisory authority for the Caribbean Netherlands.
This page is a general description of how we handle personal data. It is not legal advice. For merchants, the data-processing terms in the Merchant Agreement provide further detail about our respective roles.
