Legal

Privacy Policy

This policy explains what personal data VALIDIF processes, why, and what rights you have. VALIDIF is operated by DISSYRA Finance.

Data we process

Account data: the email address and authentication data you provide when creating an account, and the company profile you register.

API and technical data: API keys (stored hashed), request metadata, identifiers of the payments and payouts you create, and webhook delivery logs.

Contact data: what you send us by email or through the contact form.

Data we do not store

We never store card numbers or CVV. Payments are completed on a hosted checkout page and payout destinations are tokenized references. Payloads we display or email are masked.

Why we process it

To provide the service you asked for: authenticating you, executing and reconciling the operations you create, notifying you of events, supporting you, keeping an audit trail of privileged actions, and meeting our legal obligations.

Sharing

We share data with the infrastructure and email providers required to run the service, and with payment providers when executing an operation you requested. We do not sell personal data and we do not use it for advertising.

Retention

Account and operation records are kept while your account is active and afterwards for as long as required for accounting, audit and legal obligations. Webhook and audit logs are kept for a limited operational period.

Your rights

You can request access, correction, deletion or export of your personal data, and object to processing. Write to privacy@validif.com and we will respond.

Changes

If this policy changes materially, we notify account holders by email. Continued use after a change means you accept the updated policy.