Privacy Policy
LAST UPDATED · 14 JULY 2026
1. Who is responsible
pspflux is operated by Ethica ("we", "us"), based in Hungary. We are the data controller for the personal data described in this policy. Contact: hello@pspflux.com.
2. What we collect
- Account data — your email address and the credentials used to sign in. Authentication is handled by AWS Cognito.
- Connected platform data — the PSP configuration the service reads on your behalf: account structures, stores, terminals, split configurations, payout schedules, and related metadata. We do not collect cardholder data or your customers' personal data as part of the service's normal operation.
- Usage and log data — technical logs (IP address, timestamps, requests) generated when you use the service, kept for security and troubleshooting.
3. Why we process it
- To provide the service — reading, modeling, and planning based on the data you connect (performance of a contract).
- To secure and operate the service — authentication, logging, abuse prevention (legitimate interest).
- To communicate with you about your account and important changes (performance of a contract / legal obligation).
We do not sell personal data and we do not use it for advertising.
4. Where it lives
The service runs on Amazon Web Services in the European Union (Frankfurt, eu-central-1). AWS acts as our processor. We do not transfer your data outside the EU/EEA except where a subprocessor does so under appropriate safeguards.
5. Cookies & analytics
This website sets no cookies. We use Google Analytics in a cookieless, consent-denied mode: no analytics cookies are set, no identifiers are stored on your device, and Google receives only limited, cookieless signals that it aggregates into modeled traffic statistics for us (legitimate interest in understanding overall site usage). Google LLC acts as our processor for this; where these signals are processed in the United States, the transfer is covered by Google's certification under the EU–US Data Privacy Framework. The application at app.pspflux.com stores authentication tokens in your browser strictly to keep you signed in; these are essential and are not used for tracking.
6. How long we keep it
Account data is kept while your account exists and deleted when you delete your account. Connected platform data is kept only as long as needed to provide the service and can be removed on request. Security logs are kept for a limited period and then deleted.
7. Your rights
Under the GDPR you can ask us for access to, correction of, deletion of, or a portable copy of your personal data, and you can object to or ask us to restrict certain processing. Write to hello@pspflux.com and we will respond within the statutory deadline. You also have the right to lodge a complaint with your local supervisory authority.
8. Security
Data is encrypted in transit, access to production systems is restricted, and PSP credentials are stored and handled only for the purpose of providing the service. No system is perfectly secure; if a breach affects your data, we will notify you as required by law.
9. Changes to this policy
When this policy changes, we update the date at the top of this page and, for significant changes, notify you in the app or by email.