v1.1 · 19 September 2026

Privacy Policy — Shatale

Effective date: 19 September 2026


1. Data Controller

The data controller responsible for personal data processed through the Shatale platform is:

Shatale SASU

SIREN 105 278 964 · RCS Montpellier 105 278 964 · TVA FR54105278964

623 Rue du Devois, 34160 Saint-Drézéry, France

Email: privacy@shatale.com

("Shatale", "we", "us")

This Privacy Policy applies to personal data we collect in connection with the Shatale payment infrastructure platform, including our website (shatale.com), API, and related services.

> If you buy through Shatale, this is not your document. People who hold a Shatale account

> and instruct Shatale to purchase goods or services on their behalf are covered by the

> Shatale Privacy Notice, served at `GET /v1/legal/privacy`, where Shatale is the

> controller of their data. This Policy covers the Publisher relationship and the website.


2. Scope

This Policy covers:

For end user data processed on behalf of Publishers, Shatale acts as a data processor under Article 28 GDPR. The applicable terms are set out in our Data Processing Agreement (DPA) with the Publisher, and the Publisher's own privacy notice governs that relationship.

It does not cover individuals who hold a Shatale account and purchase through Shatale. For them

Shatale is the controller, not a processor, and the Shatale Privacy Notice

(`GET /v1/legal/privacy`) applies.


3. Legal Basis (GDPR)

We process personal data on the following legal bases under Article 6 GDPR:

PurposeLegal basis
Providing the Service (account management, API access)Art. 6(1)(b) — Performance of a contract
KYB verification and AML/CTF screeningArt. 6(1)(f) — Legitimate interests (see note below)
Fraud prevention and IT securityArt. 6(1)(f) — Legitimate interests
Marketing communications (with consent)Art. 6(1)(a) — Consent
Improving the ServiceArt. 6(1)(f) — Legitimate interests
Accounting, tax and record-keeping obligations that bind us directlyArt. 6(1)(c) — Compliance with legal obligation

Note on AML/CTF screening. Shatale SASU is not itself an authorised payment or electronic money institution. We carry out KYB verification and AML/CTF screening to protect the platform and to assist the licensed financial partners we work with in meeting their statutory obligations. We therefore rely on our own legitimate interests under Art. 6(1)(f), not on a statutory duty of our own. A balancing assessment of those interests against your rights is available on request.


4. Data We Collect

4.1 Publisher Account Data

When you register a Publisher account, we collect:

4.2 API Usage Data

When you use the Shatale API, we collect:

4.3 Payment Authorization Data (as Data Processor)

For authorization decisions processed through our API, we handle:

4.4 Website Data

When you visit shatale.com, we collect:

4.5 Communications

When you contact us, we retain:


5. How We Use Your Data

Data categoryPurpose
Account dataAccount creation, authentication, KYB verification, invoicing
API usage dataService delivery, debugging, capacity planning, billing
Authorization dataProcessing payment decisions, audit trail, compliance
Website dataAnalytics, fraud detection, improving user experience
CommunicationsCustomer support, product updates

We do not sell personal data to third parties. We do not use personal data for automated decision-making with legal or similarly significant effects on individuals, except as part of payment authorization processing (which is the core function of the Service and disclosed to Publishers).


6. Cookies

We use the following categories of cookies on shatale.com:

CategoryPurposeCan opt out?
Strictly necessarySession management, securityNo
AnalyticsUnderstanding usage patterns (anonymized)Yes
MarketingMeasuring campaign effectivenessYes (where applicable)

You can manage cookie preferences via our cookie consent tool or your browser settings. Withdrawing consent for non-essential cookies does not affect service functionality.


7. Sharing Personal Data

We share personal data only in the following circumstances:

7.1 Service Providers (Processors)

We use third-party processors for: cloud hosting, email delivery, analytics, fraud screening, and KYB verification. All processors are bound by data processing agreements and provide appropriate guarantees under GDPR.

7.2 Card Networks

Authorization requests are submitted to Visa/Mastercard networks as part of payment processing. These networks have their own data processing terms.

7.3 Regulated Financial Partners

Card issuance, acquiring and settlement are carried out by licensed financial partners, including the issuing partner, the acquiring bank and the BIN sponsor. Those partners receive the transaction data they need to perform and record the payment, and they act as independent controllers for that data under their own regulatory obligations.

7.4 Legal and Regulatory Requirements

We may disclose data to: regulatory authorities (ACPR, Banque de France), law enforcement, or courts when required by applicable law, including AML reporting obligations.

7.5 Business Transfers

If Shatale SASU is involved in a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction. We will notify affected parties in advance.


8. International Transfers

We are an EU-based company and primarily process data within the European Economic Area (EEA). Where we transfer data outside the EEA (for example, to cloud service providers), we rely on:

Transfers made under Standard Contractual Clauses are supplemented by the technical measures described in Section 11, including encryption in transit and at rest.

You may request a copy of applicable transfer safeguards by contacting privacy@shatale.com.


9. Data Retention

Data typeRetention period
Accounting and financial records (invoices, ledger entries, accounting books)10 years from the close of the financial year (Art. L123-22 French Commercial Code)
Publisher account dataDuration of contract + 5 years (legal obligation)
KYB/AML documents5 years after end of business relationship (Art. L561-12 French Monetary and Financial Code)
Authorization logs10 years — they are supporting accounting documents (pièces justificatives) under Art. L123-22 French Commercial Code; the PSD2 record-keeping minimum of 5 years is shorter, and the longer period applies
API logs12 months rolling
Website analytics13 months (CNIL recommendation)
Marketing opt-insUntil withdrawal of consent + 3 years
Support communications3 years

9.1 What happens when a retention period ends

Once the applicable period above has expired and no other legal obligation requires us to keep the data, it is deleted or irreversibly anonymized. That review is carried out by our compliance team; it is not an automatic process, and we will tell you the expected date on request.

9.2 What happens when you close your account or ask for erasure

Some of your data is deleted straight away; some of it is bound by the accounting, tax and

anti-money-laundering periods set out above and cannot be destroyed as soon as a relationship ends.

We set out below which is which, so that you know what to expect.

Deleted or revoked on request:

Retained in an archived state: your account record — including name, email address, telephone

number and date of birth — together with the transaction, accounting and KYB/AML records covered by

the retention periods in Section 9. Active processing stops: the account is closed, access is

revoked and recurring charges end. This is a restriction of processing within the meaning of

Article 18 GDPR — the data is no longer used for any operational purpose and is kept only to

satisfy the obligations that require it, until those periods expire.

Because part of the request is closed by archiving rather than deletion, an erasure request is

reviewed by a member of our staff and is not completed automatically. We are working to shorten

the list of what has to be archived; where that changes, this Notice will be updated and reissued

under a new version number.


10. Your Rights Under GDPR

As a data subject, you have the following rights under the GDPR (Articles 15–22):

RightDescription
Access (Art. 15)Request a copy of personal data we hold about you
Rectification (Art. 16)Request correction of inaccurate or incomplete data
Erasure (Art. 17)Request deletion of your data — see 10.1 for how we carry this out
Restriction (Art. 18)Request restriction of processing in certain circumstances
Portability (Art. 20)Receive your data in a structured, machine-readable format
Objection (Art. 21)Object to processing based on legitimate interests
Withdraw consent (Art. 7(3))Withdraw consent at any time without affecting prior processing

To exercise any right, contact privacy@shatale.com. We will respond within one month of receiving your request. Where a request is complex or where we have received several from you, that period may be extended by a further two months, and we will tell you within the first month that we are extending it and why (Art. 12(3) GDPR). We may need to verify your identity before acting on a request.

10.1 How we carry out an erasure request

You may ask us to erase your personal data at any time, and we carry the request out in two parts.

Data not covered by a statutory retention obligation is deleted or revoked: marketing and

notification preferences, marketing contact records, device tokens, sessions and access credentials.

Records covered by our accounting, tax and anti-money-laundering obligations — including your

account record and your transaction history — cannot be destroyed while those obligations run.

Complete destruction of them is restricted by law under Article 17(3)(b) GDPR. We close the

account, stop the processing and place those records in the archived state described in

Section 9.2, restricted under Article 18 GDPR, until the applicable period expires.

Because of that split, an erasure request is reviewed by a member of our staff rather than

completed automatically. We will tell you which categories were deleted, which were archived, the

legal basis for keeping each archived category, and when its period ends.

10.2 Right to Lodge a Complaint

You have the right to lodge a complaint with your national data protection authority. In France, this is the Commission Nationale de l'Informatique et des Libertés (CNIL): www.cnil.fr.


11. Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or destruction, including:

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the CNIL within 72 hours and affected individuals without undue delay, as required by Article 33–34 GDPR.


12. Children

The Service is not directed at individuals under 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a minor, we will delete it promptly.


13. Changes to This Policy

We may update this Privacy Policy. Where changes are material, we will notify Publisher account holders by email at least 30 days before the effective date. The current version is always available at shatale.com/privacy. Changes to the Notice that applies to people who buy through Shatale are announced separately, in that Notice.


14. Contact

Data Protection queries:

privacy@shatale.com

Postal:

Shatale SASU — Data Protection

623 Rue du Devois

34160 Saint-Drézéry

France