Privacy policy
Last updated: July 22, 2026
1. Preamble
This privacy policy describes how AventoPay UAB, a Lithuanian company registered under number 307634152, whose registered office is at Architektų g. 56-101, LT-04111 Vilnius, Lithuania ("Aventopay", "we"), collects, uses and protects personal data in the context of providing the Aventopay service.
It complies with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data ("GDPR") and the Lithuanian data protection law.
2. Data controller
The controller of the data collected via avento-pay.com and the Aventopay service is:
| Legal name | AventoPay UAB |
|---|---|
| Address | Architektų g. 56-101, LT-04111 Vilnius, Lituanie |
| Registration number | 307634152 |
| Data protection contact | privacy@avento-pay.com |
3. Data collected
3.1 Merchant data
When creating and using a merchant account:
- First and last name
- Email address
- Password (stored hashed with bcrypt)
- Connection data (IP address, timestamp, user-agent)
- Information related to the merchant's payment account (opaque technical identifiers)
3.2 End Customer data (payers)
When an End Customer makes a payment via the platform:
- Email address and name entered at payment (or transmitted by the Merchant)
- Customer identifier transmitted by the Merchant (
external_user_id) - Transaction amount and currency
- Aventopay unique transaction reference
- IP address and timestamp
Card data is never collected, processed or stored by Aventopay. It is entered directly in a secure form hosted on PCI DSS Level 1 certified infrastructure, and transmitted exclusively to the licensed institutions that execute the payment operations.
3.3 Navigation data
We collect anonymised technical information for service operation and security purposes: server logs, device and browser information, pages consulted.
4. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Creation and management of the merchant account | Performance of contract (art. 6.1.b) |
| Processing of payment sessions and transactions | Performance of contract (art. 6.1.b) |
| Fraud prevention and service security | Legitimate interest (art. 6.1.f) |
| Compliance with legal obligations (accounting, retention) | Legal obligation (art. 6.1.c) |
| Sending information about the service | Legitimate interest (art. 6.1.f) |
| Sending commercial communications | Consent (art. 6.1.a) — revocable at any time |
5. Data recipients
Personal data may be transmitted to the following categories of recipients:
- Licensed payment institution(s) within the European Union, which execute payment operations and perform the required regulatory checks. These institutions act as autonomous data controllers for payment operations.
- Hosting provider: Vercel Inc., which hosts the platform and acts as a data processor under GDPR.
- Competent authorities: upon legitimate request from competent judicial or administrative authorities.
No data is sold or rented to third parties for commercial purposes. The detailed list of Aventopay's sub-processors is available on /legal/subprocessors.
6. Transfers outside the European Union
Some of our sub-processors are established in the United States (notably our hosting provider). These transfers are covered by GDPR mechanisms, notably:
- The European Commission's adequacy decision concerning the EU-US Data Privacy Framework for certified organisations;
- Failing that, the conclusion of Standard Contractual Clauses (SCCs) approved by the European Commission.
7. Retention duration
| Data type | Duration |
|---|---|
| Active merchant account | For the duration of the contractual relationship |
| Closed merchant account | 3 years from closure |
| Transaction data (accounting) | 10 years (accounting and tax obligations) |
| Security logs | 12 months |
| Session cookies | Session duration (max. 30 days) |
8. Data security
We implement the following technical and organisational measures:
- Encryption of communications (TLS 1.3, HTTPS on the entire domain);
- Password hashing with bcrypt (cost factor 10);
- HMAC-SHA256 cryptographic signatures on all integrations;
- Strong cardholder authentication (SCA / 3D Secure) applied based on the payer's regulatory zone;
- Strict multi-tenant isolation between merchants in the database;
- Restricted access to personal data on a least-privilege basis;
- Logging of administrative access and critical operations.
9. Your rights
In accordance with the GDPR, you have the following rights:
- Right of access to your personal data;
- Right of rectification of inaccurate data;
- Right to erasure ("right to be forgotten") within the limits provided by law;
- Right to restriction of processing;
- Right to data portability;
- Right to object for legitimate reasons;
- Right to withdraw consent at any time, when processing is based on it;
- Right to set directives regarding the fate of your data after your death.
To exercise these rights, contact: privacy@avento-pay.com. We will respond within a maximum of one month from receipt of your request.
10. Complaints
If you believe that the processing of your personal data does not comply with applicable regulations, you have the right to lodge a complaint with the competent supervisory authority:
Valstybinė duomenų apsaugos inspekcija (VDAI)
Lithuanian State Data Protection Inspectorate
L. Sapiegos g. 17, 10312 Vilnius, Lithuania
vdai.lrv.lt
You may also refer the matter to the supervisory authority of your country of residence.
11. Cookies
The avento-pay.com website uses a limited number of cookies strictly necessary for the operation of the service:
next-auth.session-token: authentication session cookie, essential for maintaining connection in the dashboard. Duration: 30 days max.next-auth.csrf-token: cookie to protect against CSRF attacks.
No audience measurement, targeted advertising or third-party tracking cookies are used. Consent is therefore not required for these strictly necessary cookies (art. 82 of the French Data Protection Act adapted and ePrivacy directive).
12. Policy modifications
This privacy policy may be modified at any time. The date of last update appears at the top of the document. In case of substantial modification, active users will be informed by email.
13. Contact
For any question relating to data protection: privacy@avento-pay.com.
