Last updated: July 1, 2026
Decodo (UAB “Data troops”, legal entity code: 305893779, registered address: Švitrigailos str. 34, Vilnius, Lithuania and its affiliated companies (hereinafter – „Decodo“, „we“, “our” or “us”) is committed to safeguarding the personal data. This privacy policy explains how we collect, use, share, and protect your personal data, and describes your rights.
1. Personal data processing when you register for our services
Upon registration to the Decodo dashboard, you will be asked to provide your username and email address which are necessary to create your account. We also require you to specify how do you use proxies to provide you with services that may be of interest to you and to further improve our services. Without providing the above-mentioned information, you cannot create a Decodo account. We use your email address to provide essential service-related and transactional communications necessary for fulfilling our contractual obligations (e.g., password resets, account notifications, subscription renewals). These communications are not categorized as marketing emails but are based on the lawful processing ground of necessity for the performance of a contract.
Our payment service provider might ask you for additional information when administering your payments for our services from your account. To learn more about the way our payment service provider processes your data, please refer to its privacy policy (the link is provided upon request for your information). The following personal data may be collected in relation to payment processing: name, surname/company name, VAT/Sales tax code, full billing address. This data is collected directly from you. You are required to provide the information during the payment process. The data is collected for the following purposes:
To calculate VAT/sales tax
To issue invoices and comply with applicable financial and tax regulations
The legal bases for processing this personal data are: compliance with legal obligations (Article 6(1)(c) GDPR), in particular tax and financial reporting obligations; performance of a contract (Article 6(1)(b) GDPR), in connection with processing payments for our services.
We retain different categories of data for specific periods, in accordance with legal and business requirements:
Billing and transaction information: stored in our internal database for 7 years to comply with legal obligations, such as tax, accounting, and financial reporting requirements.
Account information: retained for as long as the subscription remains active, and for 2 years after the account is closed, unless a request for earlier deletion is made.
Payment service providers: our payment processors, such as Stripe, retain transactional records for the entire duration of the Stripe account. This retention is necessary to comply with applicable laws and regulations, including anti-terrorism and anti-money laundering (AML) obligations.
1A. Personal data processing when you use our proxy services
When you use Decodo’s proxy infrastructure (including residential, ISP, mobile, and datacenter proxies), the following technical data may be processed: your account authentication credentials (username or whitelisted IP address), connection timestamps, session duration, bandwidth consumed, assigned proxy IP addresses, proxy protocol used (HTTP/HTTPS/SOCKS5), and target domain requested. Decodo does not log the content of your traffic or the specific web pages you visit through our proxy infrastructure. We process connection metadata solely for the purposes of: (a) delivering and maintaining the proxy service (Article 6(1)(b) GDPR, contractual necessity); (b) calculating bandwidth usage for billing purposes (Article 6(1)(b) GDPR); (c) detecting and preventing abuse, fraud, and violations of our License Agreement, including access to prohibited targets (Article 6(1)(f) GDPR, legitimate interest); and (d) maintaining the security, integrity, and performance of our infrastructure (Article 6(1)(f) GDPR).
Controller/Processor roles for proxy services: When you use Decodo’s proxy infrastructure, both Decodo and you (the customer) act as independent data controllers with respect to any personal data that may be processed through the proxy connection. Decodo is the controller of your account data and connection metadata. You are the controller of any personal data that you collect, access, or process through the proxy infrastructure in the course of your own activities. You are solely responsible for ensuring that your use of Decodo’s proxy services complies with applicable data protection laws, including having a lawful basis for any data you collect or process using our infrastructure.
Decodo does not monitor, intercept, or store the substance of data transmitted through its proxy infrastructure. Connection metadata is retained for the duration of the active billing period plus a maximum of 90 days for abuse prevention and billing dispute resolution purposes, after which it is automatically deleted.
1B. Personal data processing when you use our automated data gathering services (Scraping API, Site Unblocker, AI Parser)
When you use Decodo’s automated data gathering services, including but not limited to the Web Scraping API, Site Unblocker, Scraping Templates, and AI Parser, Decodo processes requests on your behalf to retrieve publicly available data from specified target websites. In the course of providing these services, Decodo may process: your account credentials and API keys, request parameters (target URLs, scraping configuration, parsing instructions), technical metadata (request timestamps, response codes, bandwidth), and the retrieved data (scraped content) that passes through Decodo’s infrastructure.
Controller/Processor roles for automated data gathering services: When you use Decodo’s automated data gathering services, Decodo acts as a data processor on your behalf within the meaning of Article 28 GDPR. You, as the customer, are the data controller with respect to any personal data contained in the scraped content. The Decodo Data Processing Agreement (DPA), governs this processing relationship and forms an inseparable part of the License Agreement. As the data controller, you are solely responsible for: (a) determining the lawful basis for the collection and processing of scraped data; (b) ensuring compliance with applicable data protection laws; and (c) providing any required transparency notices to data subjects whose personal data may be collected.
2. Personal data processing when performing identity verification, related checks
At Decodo, we are committed to ensuring the security and privacy of your personal information. We are also committed to providing our users with secure and efficient access to our services. As part of our services, we use Stripe, Inc. and its European entities, Stripe Technology Europe, Limited and Stripe Payments Europe, Limited (collectively, “Stripe”) for identity verification and related checks, through the Stripe Identity product, to help us confirm your identity securely and efficiently. Additionally, we offer company verification as an alternative method for identity verification. This section in our Privacy Policy outlines how we collect, use, and protect your personal information, particularly in the context of identity verification and related checks.
For more detailed information on how Stripe handles your data when performing verification and/or related checks, please review the Stripe Privacy Policy at https://stripe.com/privacy and the Stripe Privacy Center at https://stripe.com/legal/privacy-center#stripe-identity. Stripe may also process your information independently for its own fraud prevention, security, and legal compliance purposes, as well as to improve its identity verification technology. For more details, please refer to the Stripe Privacy Policy.
2.1. The information we process and how we use it
To perform identity verification and related checks, we process certain personal information received from you and/or access information about you, which is processed by Stripe. When you initiate identity verification, Stripe collects your government-issued ID document images and a selfie photograph directly through its secure verification interface. Stripe processes this information to perform identity verification, complete checks, and generate a verification result that is provided to us. Important: Stripe will not share your biometric data (facial geometry) with Decodo (UAB “Data troops”). Biometric identifiers are processed exclusively by Stripe as an independent data controller for the sole purpose of comparing your selfie with your ID document. Decodo receives only the verification result and non-biometric data (document images, extracted text data such as name, date of birth, and document number).
Once your identity is verified and/or a check is completed, Stripe provides us with the verification result (verified, requires further input, or failed), together with data extracted from your identity document (such as your name, date of birth, and document number), captured images, and fraud risk signals. If your identity is verified and no issues are detected, the result will indicate a “verified” status. If your identity cannot be verified or there are signs of fraud, the result will indicate a failure or that additional input is required, with details explaining why. We have access to the verification result, captured images, and extracted data through Stripe.
We only use the data for the purpose specified below. We do not sell, lease, trade, or otherwise profit from the data collected, as described below.
2.2. Identification Document (ID) checks
Purpose: to verify the authenticity of your ID and ensure compliance with legal obligations.
Categories of data that might be processed: personal information extracted from your identity document, such as your name, document number, date of birth, nationality, type of document, issuing country, expiration date, and metadata associated with the image of the document, your photo on the ID document.
Legal basis: the processing of your personal data for ID verification is necessary for the legitimate interests of Decodo (Art. 6(1)(f), GDPR), to prevent fraud, ensure the security of our services. Additionally, we might be obliged to ensure compliance with the anti-money laundering (AML), know-your-customer (KYC) regulations, and other statutory obligations that mandate ID verification (Art. 6(1)(c), GDPR).
Stripe verifies identity documents by using a combination of AI models, automated heuristic analysis, and where necessary, manual reviewers, to extract and analyze information from your document and verify its authenticity against a database of known fraudulent document templates.
2.3. Photo checks and identification
Purpose: to verify your identity by comparing your image (selfie) with the image on your ID, and to detect the potential tampering or fraud.
Categories of data that might be processed: images (selfies) you provide for identification purposes.
Legal basis: Stripe will ask you to provide a live selfie photograph that is compared with the photograph on your ID document using automated biometric facial recognition technology, which extracts and compares facial geometry (biometric identifiers) to verify and confirm your identity. Stripe also analyzes the authenticity of these images and detects signs of tampering or fraud through liveness detection algorithms. Stripe processes your biometric data as an independent data controller and will not share your biometric identifiers with Decodo. Because this processing involves biometric data (a special category of personal data under Article 9 GDPR), Stripe collects your explicit consent directly within its verification flow before biometric processing takes place (Art. 9(2)(a), GDPR). Biometric identifiers generated for the comparison will be retained by Stripe for no longer than one (1) year and are not accessible to Decodo at any time.
2.4. Company Verification
Purpose: to verify your identity through your company affiliation, enable access to enterprise-tier services, and fulfill our Know Your Customer (KYC) obligations.
Categories of data that we process: when you choose to complete identity verification using company information, we collect and process the following data (personal and non-personal data): email address (your registered account email), registered company name, corporate registration number, company website, additional website(s), business targets, use case description.
Legal basis: the processing of your company verification data is necessary for the legitimate interests of Decodo (Art. 6(1)(f), GDPR). We have a legitimate interest in verifying the identity of our enterprise clients, preventing fraud, maintaining platform security, and ensuring the integrity of our verification processes. This processing is balanced and proportionate, as clients reasonably expect that enterprise-level services would require business verification.
All company verification data is collected and stored directly by us in our administrative system and linked to your registered email address. This allows us to maintain a verified status for your account without requiring individual identity verification.
2.5. Data storage
We retain your personal information only as long as necessary to provide our services or as required by law. The retention period may vary based on the type of data and legal requirements. For identity verification and related checks, Stripe stores verification data (including captured images, extracted document data, and verification results) on our behalf as our data processor. Biometric identifiers are processed and retained exclusively by Stripe as an independent controller and are not shared with or accessible to Decodo; Stripe deletes biometric identifiers within one (1) year. Other submitted identity data (non-biometric) is typically retained by Stripe for up to three (3) years, or until we request earlier deletion via the Stripe API redaction endpoint. We keep verification results for the duration of your contract with us, plus an additional five years after the contract ends. For company verification data, we retain this information for the entire duration of your account relationship with us, as it forms part of our ongoing KYC compliance requirements. If you choose to delete your account, all associated company verification data will be deleted in accordance with our standard data deletion procedures.
2.6. Contacts
If you have any questions or concerns about identity verification or related checks, please contact us at compliance@decodo.com. If you wish to find out more about your privacy rights, please refer to the „Your privacy-related rights“ section of this Privacy policy.
3. Personal data processing when you contact us
We can be contacted by various means:
you can send us an email;
you can fill in an online contact form;
you can send us a request using our live chat platform; or
you can contact us through social media.
In all these cases, we process your personal data for the purposes of responding to your inquiry and administering it. By contacting us you consent to your personal data processing, therefore the legal basis for your data processing in this case is a consent.
4. Personal data processing when using our live chat platform
When you engage with our live chat platform, we use a third-party service, DeepL translator, to facilitate communication by translating the text you submit. We process the following data: 1) messages and other text-based communication that you provide through the live chat; 2) any personal data included in those communications, such as your name or contact details. The text you submit is processed by DeepL for the purpose of real-time translation to facilitate better communication between you and our support team. By using the live chat and submitting text for translation, you provide your explicit consent for the processing of your personal data. You can withdraw your consent at any time by discontinuing the use of the live chat function. Your data is shared with DeepL SE, the service provider of the translation tool. DeepL processes the text submitted during live chat interactions solely for the purpose of translation. DeepL’s privacy policy can be reviewed
https://www.deepl.com/en/privacy
which outlines how they process and protect personal data.
We do not retain any translated data beyond the duration of the live chat session. The text submitted is processed only for the duration of the chat interaction.
5. Personal data processing for marketing purposes
Decodo may use your personal data to contact you with marketing related offers.
You will receive information about our services if you provide your contact details in the contact form on our website. We consider that by providing your information in the online form you give us a consent to contact you for purposes mentioned in this section.
In cases where applicable law permits us to contact you without a separate consent, we will contact you under the legal basis of our legitimate interests to make you an offer of our services. You can opt-out from any marketing related communication that we send you at any time by clicking an unsubscribe button in our emails or by contacting us at
compliance@decodo.com
.
6. How long do we store your data?
Decodo stores your personal data only for as long as necessary to fulfill the purposes for which the data was collected, as outlined in this Privacy Policy, or to comply with legal obligations.
We retain your personal data for up to 2 years from your last interaction with us (such as your last contact or log-in), unless a longer retention period is required or permitted by law. In particular, we may retain your data beyond this period if necessary for the establishment, exercise, or defense of legal claims, or to comply with legal obligations (e.g., tax, accounting, or regulatory requirements). Once the applicable retention period has expired, we will securely delete personal data, unless further storage is required by applicable law.
7. Data sharing
Decodo engages certain service providers to process your personal data. These data processors include, but are not limited to: customer relationship management (CRM) software providers, email and email tracking service providers, online live chat service providers, business development service providers, customer support specialists, data analytics providers, payment service providers such as Stripe, identity verification services, web hosting companies, and other technical or professional service providers. In all instances, personal data is disclosed only to the extent necessary for the provision of their respective services.
Our service providers are generally located within the European Economic Area (EEA). When engaging service providers based outside the EEA, we seek to ensure an adequate level of data protection. For providers that are based outside of the EEA, we ensure adequate safeguards are in place, such as executing data processing agreements incorporating the Standard Contractual Clauses approved by the European Commission or other appropriate legal mechanisms that ensure compliance with EU data protection requirements.
We may also disclose your personal data to state agencies, governmental authorities, law enforcement bodies, courts, or regulatory authorities where required by applicable law. This may include responding to official requests such as subpoenas, supporting investigations, complying with legal obligations, or protecting our rights, interests, and the safety of our company, employees, clients, and the general public.
8. Your privacy-related rights
You have the following rights with respect to your personal data:
to get access to your personal data and related information about processing;
to demand to correct inaccurate data;
to demand to erase your personal data or restricting the processing of your personal data when there is a legal basis for that;
to demand to transfer your personal data to another data controller or provide it directly to you in a convenient format (on conditions set in the applicable law);
in cases where your personal data is processed on a consent basis, you have the right to withdraw your consent at any time;
to object to the processing of your personal data, if the processing is based on a legitimate interest (on conditions set in the applicable law);
to contact a relevant data protection authority of your habitual residence, place of work or of an alleged infringement and file a complaint, if you believe that your data is processed unlawfully. If you like to exercise any of the above-mentioned privacy-related rights, please contact us at
privacy@decodo.com
.
9. Data security
Personal data is accessed, updated, and deleted only by authorized personnel within our company (including customer support, billing, and compliance teams), on a strict need-to-know basis, and in accordance with our internal policies, security measures, and applicable data protection laws. We implement appropriate technical and organizational measures to ensure the confidentiality, integrity, and availability of personal data, as required under Article 32 of the GDPR.
10. Updates to this Privacy Policy
This Privacy Policy may be updated or amended from time to time to reflect evolving practices, comply with new legal obligations, or for other operational considerations. In the event of substantial changes, we will inform you through appropriate communication channels, which may include electronic mail or the prominent display of a notice on our website or within our service offerings. All amendments will take effect upon their publication on our website, and the date of the latest update will always be publicly available here. Your continued engagement with our services after these adjustments take effect will constitute your acceptance of the amended Privacy Policy.
It is advisable to review this Privacy Policy regularly to understand how your personal data is collected, used, and protected.
11. Cookies
When you visit our website, we ask you for a consent to collect certain personal data with the help of cookies and other similar technologies. Cookies, pixels and other similar technologies are usually small text or image files that are placed on your device when visiting our website. We mostly use cookies on our website and they usually fall within one of the following categories:
– Essential cookies. Without these cookies we cannot provide many services that you need on the website. For example, essential cookies help remember your preferences as you move around the website.
– Functionality cookies. These cookies are used to remember information you have entered or choices you make (such as your username or language) on the website, so the next time you visit the website you will not have to set them again.
– Analytics cookies. These cookies track information about visits to the website so that we can make improvements and report our performance. For example, analyze visitor and user behavior to provide more relevant content.
– Advertising cookies. These third-party cookies are placed by third-party advertising platforms or networks to deliver ads and track ad performance. In some cases, these cookies enable advertising networks to deliver ads that may be relevant to you based upon your activities on our website and other websites (in such cases, ad serving might be based on automated decision-making).
Cookies on our website can be classified to session or persistent cookies. Session cookies are temporary and are erased when you close your browser at the end of your surfing session. Persistent cookies remain on your hard drive until you erase them or they expire. Please find cookies and other technologies used on our website in the table below:
Essential cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
COOKIE NAME
PURPOSE / DESCRIPTION
COOKIE DURATION
__cfduid
Used by the content network, Cloudflare, to identify trusted web traffic.
1 year
catAccCookies
Determines whether the visitor has accepted the cookie consent box. This ensures that the cookie consent box will not be presented again upon re-entry.
29 days
laravel_session
This cookie is used internally by the website’s owners, when uploading or renewing website content. Initiator: Script tag, page source line number 1.
1 day
m-b
Ensures visitor browsing-security by preventing cross-site request forgery. This cookie is essential for the security of the website and visitor.
6080 days
pa_enabled
Determines the device used to access the website. This allows the website to be formatted accordingly.
Persistent
XSRF-TOKEN
Ensures visitor browsing-security by preventing cross-site request forgery. This cookie is essential for the security of the website and visitor.
1 day
Functionality cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
COOKIE NAME
PURPOSE / DESCRIPTION
COOKIE DURATION
dc
Necessary for the functionality of the website's chat-box function.
Session
driftt_aid
Necessary for the functionality of the website's chat-box function.
2 years
driftt_sid
Identifies the visitor across devices and visits, in order to optimize the chat-box function on the website.
1 day
Analytics cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
COOKIE NAME
PURPOSE / DESCRIPTION
COOKIE DURATION
_dc_gtm_UA
Used by Google Tag Manager to control the loading of a Google Analytics script tag.
1 day
_ga
Registers a unique ID that is used to generate statistical data on how the visitor uses the website.
2 years
_gat
Used by Google Analytics to throttle request rate.
1 day
_gid
Registers a unique ID that is used to generate statistical data on how the visitor uses the website.
1 day
collect
Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across de vices and marketing channels.
session
Drift.Targeting.currentReferrer
Allows the website to recoqnise the visitor, in order to optimize the chat-box functionality.
Persistent
Drift.Targeting.referrerDomain
Allows the website to recoqnise the visitor, in order to optimize the chat-box functionality.
Persistent
pa
Registers the website's speed and performance. This function can be used in context with statistics and load-balancing.
Persistent
personalization_id
This cookie is set by X.com - The cookie allows the visitor to share content from the website onto their X.com profile.
2 years
Advertising cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
COOKIE NAME
PURPOSE / DESCRIPTION
COOKIE DURATION
_fbp
Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers.
3 months
_gcl_au
Used by Google AdSense for experimenting with advertisement efficiency across websites using their services.
3 months
_hjIncludedInSample
Determines if the user's navigation should be registered in a certain statistical place holder.
Session
_hjRecordingEnabled
This cookie is used to identify the visitor and optimize ad-relevance by collecting visitor data from multiple websites – this exchange of visitor data is normally provided by a third-party data-center or ad-exchange.
Session
ads/ga-audiences
Used by Google AdWords to re-engage visitors that are likely to convert to customers based on the visitor 's online behaviour across websites.
Session
Drift.Targeting.currentPageViewStarted
Necessary for the functionality of the website's chat-box function.
Persistent
Drift.Targeting.currentSessionStartedAt
Identifies the visitor across devices and visits, in order to optimize the chat-box function on the website.
Persistent
Drift.Targeting.firstVisit
Necessary for the functionality of the website's chat-box function.
Persistent
Drift.Targeting.lastVisit
Necessary for the functionality of the website's chat-box function.
Persistent
Drift.Targeting.numberOfSessions
Determines the number of visits of the specific visitor. This is used in order to make the chat-box function more relevant.
Persistent
Drift.Targeting.numberOfVisits
Determines the number of visits of the specific visitor. This is used in order to make the chat-box function more relevant.
Persistent
Drift.Targeting.previousPage
Identifies the last page visited by the visitor. This is used in order to make the chat-box function more relevant.
Persistent
fr
Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers.
3 months
GPS
Registers a unique ID on mobile devices to enable tracking based on geographical GPS location.
1 day
i/adsct
The cookie is used by X.com in order to determine the number of visitors accessing the website through X.com advertisement content.
Session
IDE
Used by Google DoubleClick to register and report the website user's actions after viewing or clicking on e of the advertiser's ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user.
1 year
MUID
Used widely by Microsoft as a unique user ID. The cookie enables user tracking by synchronising the ID across many Microsoft domains.
1 year
MUIDB
Registers data on visitors from multiple visits and on multiple websites. This information is used to measure the efficiency of advertisement on websites.
1 year
NID
Registers a unique ID that identifies a returning user's device. The ID is used for targeted ads.
6 months
pagead/1p-user-list/
Generated by Google pagead dynamic marketing to track events such as conversions or other meaningful user interactions.
Session
PREF
Registers a unique ID that is used by Google to keep statistics of how the visitor uses YouTube videos across different websites.
8 months
r/collect
This cookie is used to send data to Google Analytics about the visitor's device and behavior. It tracks the v isitor across devices and marketing channels.
Session
rc::a
Used in context with video-advertisement. The cookie limits the number of times a visitor is shown the same advertisement-content. The cookie is also used to ensure relevance of the video-advertisement to the specific visitor.
Persistent
rc::b
Used in context with video-advertisement. The cookie limits the number of times a visitor is shown the same advertisement-content. The cookie is also used to ensure relevance of the video-advertisement to the specific visitor.
Session
rc::c
Used in context with video-advertisement. The cookie limits the number of times a visitor is shown the same advertisement-content. The cookie is also used to ensure relevance of the video-advertisement to the specific visitor.
Session
test_cookie
Used to check if the user's browser supports cookies.
1 day
tr
Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers.
Session
VISITOR_INFO1_LIVE
Tries to estimate the users' bandwidth on pages with integrated YouTube videos.
179 days
YSC
Registers a unique ID to keep statistics of what videos from YouTube the user has seen.
Session
yt-remote-cast-installed
Stores the user's video player preferences using embedded YouTube video.
Session
yt-remote-connected-devices
Stores the user's video player preferences using embedded YouTube video.
Persistent
yt-remote-device-id
Stores the user's video player preferences using embedded YouTube video.
Persistent
yt-remote-fast-check-period
Stores the user's video player preferences using embedded YouTube video.
Session
yt-remote-session-app
Stores the user's video player preferences using embedded YouTube video.
Session
yt-remote-session-name
Stores the user's video player preferences using embedded YouTube video.
Session
DFTT_END_USER_PREV_BOOTSTRAPPED
A True/False indication that the site visitor previously interacted with the chat or playbooks. This helps us fetch any existing conversations.
2 years
hjViewportId
Hotjar Session Recorder. No personal data recorded.
2 years
paddlejs_campaign_referrer
Track campaigns referrers for visitors.
30 days
paddlejs_checkout_variant
Used when initiation a subscription request.
3 months
poptin_client_id
ID of the poptin, to know which poptin will be activated.
Session
poptin_every_visit_session
For display rules.
Session
poptin_new_user
Identifying new user.
Session
poptin_old_user
Identifying old user.
1 day
poptin_origin_landing_page
For display rules.
Session
poptin_referrer
Original referrer.
1 day
poptin_session
Poptin session for poptin display settings.
1 day
poptin_user_id
Unique visitor id.
1 year
SP-REFERRER
URL from which user came to website
2 months
SP-LAST_PAGE
Users last visited page
2 months
SP-CONTACT
URL of the page that user successfully completed Inquiry form
2 months
SP-AFFILIATES
URL that contains any parameters
2 months
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
COOKIE NAME
PURPOSE / DESCRIPTION
COOKIE DURATION
rc::d-15
Unclassified.
Persistent
You can control and/or delete cookies as you wish. You can delete all cookies that are already on your computer and you can set most browsers to prevent them from being placed. If you want to learn more about cookies, or how to control, disable or delete them, please visit
https://www.aboutcookies.org/
for detailed guidance.
The content of the table above is for your general information and use only. Cookies are subject to change without notice. You acknowledge that this information may contain inaccuracies or errors and is subject to change and we expressly exclude liability for any such inaccuracies or errors fully permitted by law.
This Policy was updated on: October 27th, 2025.
These terms and conditions (hereinafter in the text referred to as “Agreement” or “Terms and Conditions” or “Terms”) govern Your use of services provided by PAYBIS USA LTD, incorporated in the state of Delaware on 2 June 2021 (file number 5967173) whose address is 321 S. Boston, Tulsa, Oklahoma, 74103 (hereinafter in the text referred to as “PAYBIS”, “We”, “Us”, or “Our”).
PAYBIS is registered with the FinCEN as a Money Services Business ("MSB") operating in the capacity of a money transmitter (MSB Registration Number: 31000272911973).
This Agreement governs the provision of the Exchange Services (as defined below) to both natural (physical) persons and legal persons. Additional terms applicable exclusively to legal persons are set out in Schedule 1. Risk disclosures applicable to all Customers are set out in Schedule 2.
Pursuant to this Agreement, PAYBIS provides the exchange of Digital Assets for funds, funds for Digital Assets, or exchange of Digital Assets for other Digital Assets, available to both Individual Customers and Corporate Customers located in those States of the United States in which PAYBIS is registered or otherwise permitted to provide such services (collectively, the "Exchange Services").
The Exchange Services are available exclusively through the PAYBIS platform (the "Platform"). The Platform is a partially automated online system accessible via the PAYBIS website at https://paybis.com/ (the "Website"), the official PAYBIS mobile applications published in the Apple App Store (unique identifier: id1584641245) and Google Play Store (unique identifier: com.paybis) (the "Applications"), and the application programming interfaces, software development kits, and official embedded widgets or integration tools made available by PAYBIS and associated with the Website or Applications (the "Integration Tools").
Please read these Terms and Conditions carefully before accessing the Platform and creating Your Account, and keep them for Your future reference. By accessing the Platform, creating an Account, or using the Exchange Services, You agree to be bound by these Terms and Conditions, the Privacy Policy, and any other policies, schedules, or documents incorporated by reference, each as amended from time to time. If You do not agree, You must not access the Platform or use the Exchange Services.
Access to and use of the Exchange Services is subject to the eligibility criteria and territorial restrictions set out in this Agreement, and to any further eligibility, territorial, jurisdiction-specific, or product-specific restrictions specified elsewhere in this Agreement or in any applicable Schedule.
1. DEFINITIONS AND INTERPRETATION
1.1. Definitions. Capitalised terms used in this Agreement have the meanings set out in this Clause, unless defined inline.
Definition Meaning
Account The personal or business account created by a Customer on the Platform, enabling access to the Exchange Services.
AML/CTF Law The Bank Secrecy Act (BSA), as amended by the USA PATRIOT Act, and the implementing regulations issued by FinCEN, together with applicable OFAC regulations, applicable state anti-money laundering and counter-terrorist financing laws, and any successor instruments.
Applicable Law All applicable United States federal and state laws, regulations, rules, regulatory guidelines, orders, and decisions of any Competent Authority that apply to PAYBIS, the Customer, the Exchange Services, or this Agreement, including the BSA, the USA PATRIOT Act, OFAC regulations, applicable state money transmission and virtual currency laws, and any successor instruments.
Application The official PAYBIS mobile applications published in the Apple App Store (unique identifier: id1584641245) and Google Play Store (unique identifier: com.paybis).
Authorised Representative A natural person holding a valid power of attorney or corporate authorisation to act on behalf of a Corporate Customer.
BSA The Bank Secrecy Act, 31 U.S.C. §§ 5311–5336, as amended, and all implementing regulations promulgated thereunder
Business Day Any day other than a Saturday, Sunday, or a U.S. federal holiday, on which U.S. federal banking institutions are generally open for business.
CDD Procedures Customer due diligence and enhanced due diligence processes, including ongoing monitoring, conducted by PAYBIS to comply with AML/CTF Law, Sanctions requirements, and other applicable regulatory standards.
Competent Authority FinCEN (as the primary federal AML/BSA regulator); and any other governmental, regulatory, or supervisory authority — in each case to the extent it has regulatory, supervisory, or enforcement jurisdiction over PAYBIS, the Customer, the Exchange Services, or this Agreement.
Confirmation of the Order An email, in-Platform notification, or other communication from PAYBIS in a durable medium that sets out the Details of the Order and constitutes a binding agreement between the Customer and PAYBIS.
Consumer A natural person acting for purposes that are primarily personal, family, or household, as defined under applicable US federal and state consumer protection law.
Corporate Customer / Business Customer A legal person or other recognised legal entity that has entered into this Agreement with PAYBIS. Additional terms applicable to Corporate Customers are set out in Schedule 1.
Digital Asset A digital representation of a value or of a right that uses cryptography for security and is in the form of a coin, a token, or any other digital means, which can be transferred and stored electronically using distributed ledger technology or similar technology.
Customer Any natural or legal person that has accepted this Agreement and uses the Exchange Services. Where context requires, a reference to 'Customer' may refer to an Individual Customer or a Corporate Customer, as appropriate.
Details of the Order The invoice number, type and amount of Digital Assets, applicable fiat currency amount, exchange rate (if applicable), fee schedule, settlement date, and any other order-specific information communicated in the Confirmation of the Order.
Exchange Order (or "Order") Any of the following instructions initiated by You via the Platform: (a) purchase of Digital Assets from PAYBIS (Exchange Order — Buy); (b) sale of Digital Assets to PAYBIS (Exchange Order — Sell); (c) exchange of one Digital Asset for another Digital Asset (Exchange Order — Swap), where PAYBIS acts as principal counterparty.
FinCEN The Financial Crimes Enforcement Network, a bureau of the United States Department of the Treasury, responsible for administering and enforcing the BSA and related financial crime prevention regulations.
Individual Customer A natural (physical) person who has agreed to this Agreement and uses the Exchange Services on the Platform for personal purposes.
Insolvency Event Any of the following: (a) voluntary petition under Chapter 7 or Chapter 11 of the US Bankruptcy Code (11 U.S.C. § 101 et seq.); (b) an assignment for the benefit of creditors (ABC); (c) appointment of a US court-ordered receiver; (d) commencement of state insolvency proceedings; (e) general inability to pay debts as they fall due under applicable law; or (f) any equivalent proceeding in any jurisdiction.
Integration Tools Application programming interfaces (APIs), software development kits (SDKs), and official embedded widgets or integration tools made available by PAYBIS and associated with the Website or Applications.
Payment Recipient A legal entity within the PAYBIS group – including holding companies, parent companies, subsidiaries, branches, or other affiliated entities – that may, under a separate written agreement with PAYBIS, participate in processing or settling an Order.
Personal Data Any information relating to an identified or identifiable natural person, as defined under applicable US federal and state privacy law, including the California Consumer Privacy Act (CCPA) where applicable.
Platform The partially automated online system operated by PAYBIS, accessible via the Website, the Applications, and the Integration Tools, through which the Exchange Services are provided.
Privacy Policy PAYBIS' privacy policy available at https://paybis.com/policies/privacy-policy/, as amended from time to time.
Request for the Order Your initiation of an Order on the Platform, specifying the type and amount of Digital Assets and Your acceptance of these Terms. A Request for the Order is not itself binding and is a preliminary step to the Order process.
Restricted Jurisdiction A jurisdiction in which PAYBIS does not provide the Exchange Services, as updated by PAYBIS from time to time.
Sanctions Economic or financial sanctions administered or enforced by the European Union (including EU Council Regulations), the United Nations Security Council, the United States (including OFAC), the United Kingdom (including OFSI), or any other competent sanctions authority.
Services The Exchange Services (including Buy, Sell, and Swap of Digital Assets) provided to both Individual Customers and Corporate Customers, as further described in these Terms and Conditions.
Transaction The exchange of Digital Assets for funds, funds for Digital Assets, or one Digital Asset for another, entered into between You and PAYBIS pursuant to an Exchange Order. A Transaction begins on submission of the Request for the Order and is complete on the final settlement.
UBO / Ultimate Beneficial Owner A natural person who ultimately owns or controls a legal entity or legal arrangement, within the meaning of the AML/CTF Law.
Website The PAYBIS website at https://paybis.com.
1.2. Interpretation. To ensure clarity and consistency throughout the Agreement, the provisions of this Agreement shall be interpreted in accordance with the following guiding principles:
(a) References to Clauses and Schedules are to Clauses and Schedules of this Agreement, unless indicated otherwise;
(b) Headings of each Clause or Section are for convenience only and do not affect interpretation of this Agreement;
(c) References to legislation include any amendment, re-enactment, or replacement and any subordinate legislation;
(d) "Including" and "in particular" are illustrative and are not words of limitation.
(e) The singular includes the plural and vice versa;
(f) A reference to 'writing' or 'written' includes any durable medium (including email and in-Platform notifications);
(g) Where PAYBIS is required to act 'reasonably', this means taking into account all relevant circumstances including regulatory obligations, risk management protocols, and the legitimate interests of all Customers;
(h) In the event of any conflict or inconsistency: (a) Schedule 1 prevails over the main body insofar as it relates to Corporate Customers; (b) the more specific provision prevails over the more general; and (c) the more recently enacted provision prevails in the event of a temporal conflict.
2. MAIN PRINCIPLES FOR THE PROVISION OF THE EXCHANGE SERVICES
2.1. Use of Exchange Services. To use Our Exchange Services, You need to successfully complete Your Account registration process, including compliance with Our CDD Procedures. If these conditions are not met, PAYBIS will: (i) decline to establish a business relationship with You; (ii) refuse to process any Orders; and/or (iii) terminate any existing business relationship with You.
2.1.1. Additional Requests. PAYBIS reserves the right to request additional information and documents from You if required by Applicable Law and PAYBIS' internal procedures. If You do not provide the requested information or documents, PAYBIS may limit Your access to the Platform and the delivery of Exchange Services.
2.1.2. Accuracy of Data. You are responsible for ensuring that the information You provide during registration and throughout Your use of the Exchange Services is accurate, complete, and current. You warrant that all information You provide (including personal identification documents, contact details, principal residency, and any other requested information) is true, reliable, and up-to-date, and You agree to promptly update Your information if any changes occur. If You do not notify PAYBIS about changes to Your email or postal address, any notices PAYBIS sends to You will continue to be sent to the contact details provided in Your Account and these shall be deemed properly delivered to, and received by, You.
2.1.3. Number of Accounts. Unless PAYBIS requires or permits otherwise, You may hold only one Account. Holding more than one Account without PAYBIS' approval may result in measures under the Suspension and Termination provisions of this Agreement.
2.1.4. Account Suspension. PAYBIS reserves the right to suspend Your Account and the provision of the Exchange Services if PAYBIS suspects You to be in violation of these Terms and Conditions, the Privacy Policy, or Applicable Law.
2.2. Authentication Systems. You may only access the Platform if You have sufficiently authenticated Your identity and passed our identity verification procedures.
2.2.1. Authentication. Identity verification and authentication are conducted using third-party verification services, manual reviews by our compliance team, and multi-factor authentication. The exact authentication and verification requirements will depend on Your use of the Exchange Services, the nature of Your activity on the Platform, and various other risk-based factors solely determined by PAYBIS.
2.2.2. Account Access. To maintain the security of Your Account, you agree to implement and maintain the following protective measures:
a) Never share Your login credentials, or any other security data with any third party;
b) regularly update the Application and the operating system of Your device;
c) never share Your screen with anyone while logged in to Your Account, including through the use of remote desktop, remote access, or screen-sharing software.
2.2.3. Impersonation and Fraud. PAYBIS will never ask for Your codes, or any other login credentials of Your Account. Any such direct, unsolicited outreach claiming to be from PAYBIS is fraudulent. You acknowledge that unauthorized third parties and fraudulent actors frequently attempt to impersonate PAYBIS employees, support agents, or compliance teams, and You agree to remain vigilant against these unauthorized misrepresentations.
2.2.4. Account Security and Restrictions. PAYBIS may take certain actions and restrict Your Account or otherwise limit Your access to certain Exchange Services or Digital Assets, based on confidential criteria essential to PAYBIS' risk management and security protocols. PAYBIS reserves the right to implement these restrictions if You breach these Terms and Conditions, or if PAYBIS determines there is potential fraudulent activity associated with Your Account, in order to protect the overall security of Your Account and the Platform. PAYBIS is not obligated to disclose the specific details, parameters, or procedures of its risk management and security protocols to You or any third party.
2.3. Prohibited Activities and Acceptable Use. By accessing the Platform or using the Exchange Services, You unconditionally agree to maintain the highest standards of integrity, comply with all regulatory frameworks, and strictly adhere to the operational boundaries established in these Terms and Conditions. Any use of the Exchange Services outside of these parameters is strictly prohibited.
2.3.1. General Restrictions. You agree not to use the Exchange Services or the Platform for any activity that violates Applicable Law, infringes upon third-party rights, or breaches these Terms and Conditions. You are strictly prohibited from attempting to, or directly engaging in, actions that:
a) engage in any activity that is illegal, defamatory, threatening, intimidating, or harassing;
b) impersonate any person or entity, or misrepresent Your affiliation with any person or entity;
c) disguise, conceal, or manipulate Your location through IP proxying, Virtual Private Networks (VPNs), or other technical methods;
d) violate, misappropriate, or infringe upon the intellectual property, publicity, privacy, or other proprietary rights of PAYBIS or any third party;
e) violate any Applicable Law or regulatory requirement;
f) utilize the Exchange Services for any unauthorized or illicit purpose, including but not limited to gambling, illicit drug trafficking, human trafficking, terrorist financing, unlicensed weapons trade, fraudulent schemes, or scams;
g) interact with the dark web, execute transactions involving sanctioned persons or jurisdictions, or engage in any conduct that breaches Anti-Money Laundering (AML) or Counter-Terrorist Financing (CTF) obligations, including the obligation to disclose trust relationships and to comply with cease-and-desist instructions; or
h) use Your Account or the Exchange Services in a manner that PAYBIS or any card network reasonably believes to be an abuse of the card system or a violation of card scheme or network rules.
2.3.2. Consequences of Breach. Any engagement in, or attempt to engage in, any of the prohibited activities listed in this Agreement constitutes a severe and material breach of these Terms and Conditions. In the event that PAYBIS determines, or reasonably suspects, that You have violated any of these provisions, PAYBIS reserves the immediate right to take any of the actions set out in this Agreement.
2.4. Eligibility. At the time of registering Your Account, and continuously throughout the entire duration of using the Exchange Services, You represent and warrant the following:
(a) Age and Legal Capacity: You are at least 18 years of age (or such higher age of majority applicable in Your jurisdiction of residence) and possess the full legal capacity to form a binding contract with PAYBIS;
(b) Contractual Capacity: You have sufficient capacity to enter into legally binding agreements;
(c) No Prior Suspension: You have not previously been suspended or terminated from using the Exchange Services;
(d) Non-Resident of Restricted Areas: You are not located in, or a resident or citizen of, any Restricted Jurisdiction;
(e) Compliance with Local Law: You will not use the Exchange Services if any Applicable Law in Your or any other jurisdiction prohibits You from doing so;
(f) Acting on Own Behalf: You are acting solely in Your own name and on Your own behalf, and not as an intermediary, broker, agent, or trustee for any third party (unless expressly authorized in writing by PAYBIS); and
(g) Sanctions Compliance: You are not subject to economic or financial sanctions imposed by the European Union, the United Nations, the United States (including OFAC), or the United Kingdom, nor You are national or citizen of any country subject to such comprehensive sanctions.
2.5. No Exchange Services for Minors. The Exchange Services are intended solely for persons who are at least 18 years of age. The Exchange Services are not directed to, and PAYBIS does not knowingly collect or solicit personal information from, persons under the age of 18. If PAYBIS discovers or is notified that it has inadvertently collected personal information from any person under 18, PAYBIS will promptly delete that information and terminate the relevant Account. If You believe PAYBIS has collected personal information from a person under 18, please contact PAYBIS immediately at dpo@paybis.com.
2.6. Modification and Refusal of Exchange Services. The availability of any Exchange Services may be restricted, suspended, or refused at any time based on Your location, changes in Applicable Law, or PAYBIS' internal compliance and risk management policies. PAYBIS reserves the right, at its sole discretion and at any time, to restrict, suspend, or reject registration on the Platform by certain persons, or by residents or citizens of certain jurisdictions.
2.7. Applicability, Eligible Jurisdictions, and Exchange Service Restrictions. Access to and use of the Exchange Services is strictly conditioned upon the Customer's classification and geographic location. The Exchange Services are segmented and restricted as follows (excepting Restricted Jurisdictions defined in Clause 2.7.2)
2.7.1. Individual Customers: Individual Customers are eligible to access and use Exchange Services exclusively within the United States of America. Any natural persons residing outside the United States are strictly ineligible to establish an Account or access any Exchange Services under this Agreement.
2.7.2. Restricted Jurisdictions. PAYBIS strictly prohibits the provision of its Exchange Services in certain jurisdictions ("Restricted Jurisdictions") in accordance with our regulatory and compliance obligations.
2.7.2.1. Global Restrictions: The jurisdictions where the provision of all Exchange Services is entirely prohibited include: Afghanistan, Belarus, the Central African Republic, Cuba, the Democratic Republic of the Congo, Ethiopia, Iran, Iraq, Lebanon, Louisiana (state of the US), Libya, Mali, Myanmar, New York (state of the US), Nicaragua, North Korea, Russia, Somalia, South Sudan, Sudan, Syria, Venezuela, Yemen, and geographies with unrecognised or disputed status.
2.7.2.2. United States Restrictions: Notwithstanding any other provision of this Agreement, the provision of any Exchange Service to Individual Customers is entirely prohibited within the US states and territories of Louisiana and New York. Additional state-level service exclusions and partner-routing constraints for Corporate Customers are set forth under Schedule 1.
2.7.2.3. Additional Restrictions. The list of US states and territories in which the Swap Orders are not available is as follows: Alabama (state of the US), Alaska (state of the US), Arkansas (state of the US), Minnesota (state of the US), Nevada (state of the US), New Mexico (state of the US), North Dakota (state of the US), Puerto Rico (unincorporated territory of the US), Vermont (state of the US), and Washington (state of the US).
2.7.2.4. Digital Asset Specific Restrictions. Paybis does not accept fiat-to-Digital Asset Orders involving Axie Infinity (AXS), Binance Coin (BNB), Chiliz (CHZ), Holo (HOT), SushiSwap (SUSHI), and TRON (TRX) from Individual Customers residing in Alabama, Alaska, Arkansas, Minnesota, Nevada, New Mexico, North Dakota, Puerto Rico, Vermont, and Washington. Paybis will reject such Orders if we detect that You perform them as a resident of the above-mentioned US states and territories.
2.7.2.5. Texas. While Individual Customers from Texas are allowed to submit fiat-to-Digital Asset Orders (e.g. Credit Card to Bitcoin) or Digital Asset-to-fiat Orders (e.g. Bitcoin to Credit Card) on Paybis, there are some restrictions that apply: 1) Paybis does not accept Orders that involve stablecoins (e.g., Tether) from the Customers from Texas; and 2) Paybis will reject such Orders if we detect that You perform them as a resident of Texas. By submitting stablecoin Orders to Paybis, You confirm that You are not a resident of Texas and You are eligible to purchase stablecoins through Paybis.
2.8. Use of Affiliates and Exchange Service Providers for Execution and Operations. PAYBIS may perform, or arrange the performance of, any part of the Exchange Services — including order routing, execution, liquidity sourcing, settlement, and other backend or technical functions — through its affiliates, group companies, or third-party service providers, whether acting as execution agent, liquidity provider, sub-custodian, or in another operational capacity. Any such arrangement is internal to PAYBIS' provision of the Exchange Services and does not create any contractual or other relationship between You and the relevant affiliate or service provider. The PAYBIS entity identified to You before submission of Your Order remains Your sole counterparty and remains responsible for performing its obligations under this Agreement. PAYBIS remains responsible for the acts and omissions of any affiliate or service provider used in this way to the same extent as for its own, and no such arrangement reduces Your rights or PAYBIS' liability under this Agreement or under Applicable Law. PAYBIS may share Your information with such affiliates and service providers to the extent necessary for these purposes and permitted by Applicable Law, in accordance with the Privacy Policy.
2.9. PAYBIS USA does not offer, provide, or facilitate the custody or administration of Digital Assets and holds no Digital Assets for any user. Nothing herein is an offer, solicitation, or recommendation to use any such service. Where the user accesses such services, they are provided solely by SIA "Paybis Europe" under its separate Terms and Conditions and jurisdictional restrictions, available here: https://paybis.com/policies/terms-of-service/. By accepting these Terms, the user also accepts SIA "Paybis Europe's" Terms and Conditions.
3. TRANSACTION ORDERS
3.1. General Provisions for Orders. This Clause 3 sets out the rules common to all Orders. Where any specific order rules conflict with the general rules, the specific order rules take precedence.
3.1.1. Who may place Orders. You may submit Orders only via Your Account. Each Order requires that You have completed the CDD Procedures applicable to the relevant Exchange Service and verification level, and that You comply with the authentication requirements set out in Clause 2.2.
3.1.2. Submission of Orders. To submit an Order, You must (i) provide valid and correct data to each requirement on the Platform, and (ii) confirm the Order by clicking the relevant confirmation button or equivalent action. Receipt of Your submission will be confirmed to You promptly on the Platform. Before submission, the Platform will display the type of Order, the contracting PAYBIS entity, the applicable fees and limits (if any). You may only bring claims arising in connection with an Order against the PAYBIS entity that entered into, or processed, that Order.
3.1.3. Limits. Each Order must meet the minimum value displayed on the Platform. Maximum limits may apply per Order, per day, per month, or per Account, depending on Your verification level, jurisdiction, and risk profile. Limits may be varied at any time.
3.1.4. Fees. The fee model applicable to Your Order depends on the type of Order. Any applicable fee for the specific Order will be displayed to You on the Platform before You confirm the Order.
3.1.5. Pricing Methodology. Before You confirm an Order, PAYBIS displays to You either a firm price for the relevant Digital Asset or the method by which that price is determined, together with any applicable fees. The price quoted to You is valid only for the limited period indicated on the Platform, if You do not confirm the Order within that period, the quote expires and a new price may be displayed reflecting the market conditions then prevailing. PAYBIS executes Your Order at the price displayed to, and confirmed by, You at the time the Order is confirmed by You.
3.2. Authority and independent action. PAYBIS processes Orders strictly based on the explicit instructions, data, and parameters You provide. By submitting an Order, You acknowledge that You are acting independently and that PAYBIS has no obligation to exercise any specialised duty of care regarding Your financial outcomes (except where strictly required by Applicable Law and/or agreed otherwise in this Agreement). You bear sole responsibility for all trading decisions and actions.
3.3. Reasonable efforts to process Orders. PAYBIS undertakes to make reasonable efforts to process Orders in a timely manner. PAYBIS does not guarantee that any Order will be accepted, executed, or settled at any particular time. PAYBIS may delay the fulfilment of an Order in the following circumstances:
(a) PAYBIS perceives a risk of illegal activity, fraud, or violation of Applicable Law and/or its procedures;
(b) Unexpected increases in transaction volumes (e.g., on a weekend or bank holiday);
(c) Latency, disruption, congestion, or other delay on the relevant distributed-ledger network;
(d) Incorrect instructions or address information entered by You;
(e) Applicable Law or a subpoena, court order, or government order requires the delay.
3.4. Right to refuse Orders. PAYBIS may refuse to process or execute any Order if:
(a) processing the Order would result in non-compliance with Applicable Law or PAYBIS' internal policies;
b) Processing the Order would pose an unacceptable risk to PAYBIS (credit, reputational, operational, or other);
c) There are insufficient funds (fiat) or Digital Assets to cover the Order and any applicable fees.
3.5. Force majeure and system failures. PAYBIS is not responsible for delays or failures arising as a consequence of problems in telecommunications, computer, or other systems; the blocking or closure of accounts; the freezing or holding of funds; political regime changes; civil strife; or the actions of third parties beyond PAYBIS' reasonable control. PAYBIS may temporarily hold funds transferred from You if there are attempted attacks, hacking attempts, or cheating scripts targeting the Platform.
3.6. Liability for incorrect information. If You provide inaccurate or false information when submitting an Order (including, for example, a bank account number that belongs to a third party, or an incorrect destination wallet address) which causes the Order to fail, the costs and fees associated with refund, reversal, or remediation shall be borne by You. In implementing the return, all commission costs for Digital Asset or fiat transfers are deducted from the funds received from You.
3.7. Reversal and Cancellation. PAYBIS may cancel or reverse an Order in the following circumstances:
(a) Reversal for cause. If PAYBIS' examination reveals a violation of Applicable Law or this Agreement.
(b) Technical errors. Due to unforeseeable and serious technical errors over which PAYBIS has no influence, an Order that has been concluded may be reversed if it contains an obvious error regarding price, volume, or Digital Asset that would be immediately recognisable to a reasonable Customer.
(c) Abusive behaviour. PAYBIS may reverse or cancel an Order in case of abusive behaviour by You towards PAYBIS, the Platform, or while using the Exchange Services, including the exploitation of loopholes or manipulation of the Platform.
4. EXCHANGE SERVICES
4.1. Nature of Exchange Services. PAYBIS offers Exchange Services under which You may (i) buy Digital Assets from PAYBIS in exchange for fiat funds; (ii) sell Digital Assets to PAYBIS in exchange for fiat funds; or (iii) exchange one Digital Asset for another Digital Asset with PAYBIS ("Swap"). In an Exchange Order, PAYBIS is Your counterparty: the trade is concluded directly between You and PAYBIS. PAYBIS is not acting as broker, investment adviser, or agent for You in connection with any Exchange Order.
4.1.1. Binding Agreement. The Exchange Order is entered into at the moment when You submit a Request for the Order and receive a Confirmation of the Order from PAYBIS. The Confirmation of the Order constitutes a binding agreement between You and PAYBIS. Prior to the Confirmation of the Order, no binding obligation arises from a Request for the Order.
4.1.2. Completion of an Exchange Order. An Exchange Order is completed when: (i) PAYBIS transfers the required amount of the purchased Digital Asset to the wallet of Your choice (purchase); (ii) PAYBIS transfers the required fiat amount to the account You have indicated (sale); or (iii) in the case of a Swap, PAYBIS credits or transfers the target Digital Asset to the wallet or Account You have indicated, against Your delivery of the source Digital Asset.
4.1.3. Limitation. PAYBIS shall not be liable for errors resulting from Your own inaccurate instructions, breach of this Agreement, from third-party system failures outside PAYBIS' control, or from errors You failed to report within the period specified above.
4.1.4. Digital Asset Irreversibility. You acknowledge that Digital Asset transactions confirmed on the relevant distributed ledger are generally irreversible, and that PAYBIS' ability to remediate errors in such transactions may be technically limited or impossible where the transaction has been confirmed on-chain. PAYBIS will take commercially reasonable steps to assist You but cannot guarantee recovery of confirmed on-chain transactions.
4.2. Destination Address Requirements. You are solely responsible for providing a valid, accurate, and compatible destination wallet address. PAYBIS will deliver Digital Assets to the address You provide and has no obligation to verify that the address is under Your ownership or control. PAYBIS has no obligation to attempt to redirect Digital Assets sent to an incorrect address. You bear sole responsibility for ensuring the accuracy of all wallet addresses submitted. Once a transaction is broadcast to the relevant network, PAYBIS has no ability to reverse or redirect it. PAYBIS is not responsible for any loss or error arising from Your use of an incompatible wallet address, an unsupported address format (including smart-contract or multi-signature addresses not supported by PAYBIS), or an address belonging to a third party, exchange, or platform. You should verify wallet compatibility before submitting an Order.
4.3. Supported Digital Assets. The range of Digital Assets available for exchange is determined by PAYBIS at its sole discretion and is subject to change without prior notice. The current list of supported Digital Assets is displayed on the Platform. PAYBIS makes no representation that any particular Digital Asset will remain available on the Platform at any given time.
5. FEES, PAYMENT TERMS AND TAXES
5.1. Payment Obligation. You agree to pay PAYBIS all applicable service fees charged for Transactions conducted on or through the Platform. You will be fully informed of the exact fees applicable to Your transaction before You submit any Order. Exchange Service fees become due once PAYBIS accepts Your Request for the Order. If a different due date is set out in the Confirmation of the Order, that date shall apply.
5.2. Tax Responsibilities and Regulatory Reporting. You are solely and exclusively responsible for determining, reporting, and paying any and all taxes, duties, or levies that apply to Your transactions or use of the Exchange Services under Your local jurisdictions. PAYBIS does not provide tax, accounting, or financial advice of any kind.
5.3. Mandatory Reporting. You acknowledge and agree that PAYBIS may be legally required to report Your Transactions and financial data to competent tax and regulatory authorities under relevant international frameworks and may be subject to similar regional reporting mandates. Such reporting may include gross proceeds from the disposition of digital assets, cost basis information, and other information required, as required by Applicable Law.
5.4. No Tax Advice. Nothing in this Agreement or in any communication from PAYBIS constitutes tax advice. You are solely responsible for determining Your tax obligations arising from Your use of the Exchange Services and for timely filing all required tax returns and paying all applicable taxes. PAYBIS strongly recommends that You consult a qualified and independent tax advisor.
6. SUSPENSION
6.1. Ongoing Monitoring and Security Checks. PAYBIS is required, under Applicable Law and its own risk-management framework, to continuously monitor the transactional behaviour and Account activity of its Customers. Any Order, transaction, deposit, or withdrawal may be subject to review, delay, suspension, or freezing. Whether such a measure is applied depends on a range of factors, including whether the relevant Order or activity appears unusual, suspicious, or inconsistent with Your prior behaviour, as assessed by PAYBIS' internal security, fraud-detection, and compliance systems. Where an Order is selected for individual review, fulfillment may be subject to longer waiting periods than would otherwise apply.
6.2. Grounds for Suspension. PAYBIS may apply any of the measures described in this Clause where it has reasonable grounds to believe, or is required by Applicable Law to act on the basis, that one or more of the following circumstances exists:
6.2.1. a breach, or suspected breach, of this Agreement or any policy incorporated into it;
6.2.2. a requirement under Applicable Law, or a request, order, or direction from a competent court, regulator, law-enforcement authority, or other public body;
6.2.3. a reasonable suspicion of fraud, money laundering, terrorist financing, sanctions evasion, market abuse, or other unlawful, prohibited, or fraudulent activity;
6.2.4. a reasonable belief that Your Account has been, or is at risk of being, accessed without authorisation, compromised, or used by a third party;
6.2.5. the provision by You of information that is false, inaccurate, incomplete, outdated, or misleading, or Your failure to complete or pass identity verification, due-diligence, or source-of-funds checks;
6.2.6. a dispute, uncertainty, or conflicting claim regarding the ownership of, or entitlement to, Your Account;
6.2.7. a credit, insolvency, security, or operational risk that PAYBIS reasonably considers material; or
6.2.8. any other circumstance in which PAYBIS reasonably considers that a measure is necessary or appropriate to protect You, other Customers, PAYBIS, the integrity of the Platform, or to comply with its legal or regulatory obligations.
6.3. Examination of Cause. Where grounds for contractual or regulatory action exist or are reasonably suspected, PAYBIS shall conduct an objective and factual examination to determine whether the suspicions are substantiated. During the course of this examination, PAYBIS reserves the right to implement any of the following administrative measures on either a temporary or permanent basis:
6.3.1. Restricting Specific Exchange Services: Restricting Your ability to utilize particular Platform features or Exchange Services;
6.3.2. Freezing Account Functionalities: Freezing targeted operational functions within Your Account; and/or
6.3.3. Suspending the Account in Full: Suspending Your Account in its entirety, thereby completely revoking Your access to the Account and the Platform.
6.4. Duration and Lifting. Any measure applied under this Clause will remain in place only for as long as the grounds giving rise to it continue to exist, or for as long as PAYBIS is required or permitted to maintain it under Applicable Law. If an Order could not be carried out because of a measure taken under this Clause, PAYBIS shall not be required to allow You to place a fresh Order at the same price, rate, or terms as the Order that was affected by the suspension, freeze, block, or cancellation; any new Order will instead be subject to the market conditions prevailing at that time.
6.5. Notice. In case PAYBIS suspends, freezes, blocks, reverses, or cancels your Order or Account, PAYBIS will give notice to You, unless prohibited by Applicable Law from doing so. PAYBIS is not obligated to disclose any findings or information acquired by its security and risk-management procedures.
Best AI Website Maker