All documentsLEGAL DOCUMENTS

Privacy Policy

Rules for processing and protecting personal data.

Privacy Policy

Download source PDF (RU)
Effective 26 July 2026Official source document in Russian

1. General Provisions

This Privacy Policy describes how HOT GATE TECHNOLOGY LTDA, operating under the PayHot brand, collects, uses, stores, transfers, and protects personal data when the https://pay.hot Website, Account, API, payment forms, Telegram bots, applications, and other PayHot interfaces are used.

The Policy applies to Website visitors, Merchant representatives and employees, Payers, bulk payout recipients, applicants for connection, support service Users, and other individuals whose data is processed in connection with the Platform.

PayHot is a technology platform. Payments, transfers, conversions, refunds, and settlements are directly processed by independent Partner Providers. Such Partners may independently determine the purposes and means of processing certain categories of data in accordance with their policies and applicable law.

2. Controller and Contact Details

The Platform Operator and personal data controller to the extent of its own processing purposes is HOT GATE TECHNOLOGY LTDA, CNPJ 67.633.679/0001-27, NIRE 33.2.1494553-4, address: Avenida Marechal Câmara, 160, Sala 1107, Centro, Rio de Janeiro, RJ, CEP 20.020-907, Brazil.

Privacy questions, requests to exercise rights, and questions about personal data processing may be sent to team@pay.hot.

3. Key Terms

Personal Data — information relating to an identified or identifiable natural person.

Processing — any operation involving Personal Data, including collection, recording, storage, use, transfer, analysis, blocking, and deletion.

Merchant — a person or organisation using PayHot to connect payment methods, receive transaction statuses, access analytics, and use other technology functions.

Payer — a User who pays for a Merchant's goods or services through an available payment interface.

Partner Provider — a bank, acquirer, payment institution, money transfer operator, cryptocurrency processor, bulk payout provider, or other independent Partner performing a financial transaction.

Automated Analysis — the use of rules, algorithms, and machine-learning models to assess risk and detect anomalies, fraud, and suspicious activity.

4. Data We Process

4.1. Registration and Contact Data

  • first name, last name, alias, and position;
  • email address, telephone number, and Telegram contact;
  • Account data, settings, sign-in history, and confirmation history;
  • the contents of support requests and correspondence with PayHot personnel.

4.2. Merchant and Project Data

  • Project name, domains, links to a website, application, Telegram bot, and advertising materials;
  • descriptions of goods and services, customer geography, traffic sources, average transaction value, and expected turnover;
  • registration and corporate documents and information about representatives and beneficial owners where requested as part of a review;
  • information about the risk category, review results, limits, and connected payment methods.

4.3. Transaction Data

  • transaction identifier, amount, currency, date, time, status, and purpose;
  • order, Merchant, Payer, and Partner Provider identifiers;
  • masked payment instrument details, issuing bank, payment method, and technical response codes;
  • information about refunds, disputes, chargebacks, bulk payouts, and settlements;
  • cryptocurrency wallet addresses, network, transaction hash, asset, and AML assessment results.

Full bank card details, including the complete card number and security code, are normally processed by the relevant acquirer or payment Partner. The amount of data available to PayHot depends on the technical arrangement for the particular payment method.

4.4. Technical Data

  • IP address, device type, operating system, browser, and interface language;
  • session identifiers, cookies, event logs, and request date and time;
  • information about errors, performance, API requests, and webhooks;
  • data required to protect an Account, prevent attacks, and investigate incidents.

4.5. Risk Screening Data

  • results of screening against sanctions, restriction, and other risk lists;
  • information about politically exposed persons and related persons where such screening is required;
  • anti-fraud signals, behavioural indicators, and risk scores;
  • information about source of funds and transaction purpose provided by the User or a Partner.

5. Data Sources

We receive data directly from Users and Merchants, through Platform interfaces and APIs, from Partner Providers, technical and anti-fraud services, public registers, public authorities, open sources, and other persons having a lawful basis to provide the data.

6. Processing Purposes and Legal Bases

Providing the Platform — registration, Account, API, support, and the creation and routing of requests. Legal basis: performance of a contract and steps taken before entering into a contract.

Connection and review — reviewing the Project, identity, authority, risk category, and available methods. Legal basis: performance of a contract, legitimate interests, and compliance with Partner requirements.

Processing transactions — transmitting payment instructions, providing statuses, refunds, payouts, and reconciliation. Legal basis: performance of a contract and action at the User's request.

Security and anti-fraud — transaction analysis, attack blocking, and investigation of suspicious activity. Legal basis: legitimate interests, fraud prevention, and protection of rights.

AML and sanctions controls — screening wallets, transactions, sources of funds, and risk lists. Legal basis: compliance with law, legitimate interests, and Partner requirements.

Legal obligations — responding to authorities and maintaining accounting and evidentiary records. Legal basis: compliance with a legal obligation and the exercise of rights in legal proceedings.

Analytics and development — statistics and improvements to the interface, quality, and stability. Legal basis: legitimate interests or consent for optional technologies.

Marketing communications — news, offers, and invitations. Legal basis: consent or legitimate interests with an option to opt out.

Where Processing is based on consent, the User may withdraw it at any time. Withdrawal does not affect the lawfulness of Processing performed before withdrawal and does not cancel Processing required under another legal basis.

7. Automated Analysis and Anti-Fraud

PayHot and Partner Providers may use automated rules, statistical models, and machine learning to assess transactions and Accounts. The analysis may take into account payment speed and sequence, repeat attempts, technical parameters, changes in usual behaviour, links between transactions, wallet risk, and other indicators.

The analysis may result in an additional review, restriction of a feature, a request for documents, a change in transaction routing, temporary suspension, or a Partner Provider's refusal to process a transaction.

The User may contact support to request an explanation or review of a decision where provided by applicable law.

8. Disclosure to Third Parties

To the extent necessary, data may be disclosed to:

  • banks, acquirers, payment institutions, money transfer operators, bulk payout systems, and cryptocurrency processors;
  • providers of identification, KYC/KYB, anti-fraud, AML analysis, sanctions screening, and information security;
  • providers of hosting, cloud infrastructure, communications, analytics, support, and development services;
  • professional advisers, auditors, and insurers subject to confidentiality obligations;
  • public authorities, courts, and law enforcement agencies where disclosure is required by law or necessary to protect rights;
  • successors in the event of a reorganisation, sale of the business, or asset transfer, subject to confidentiality requirements.

A Merchant or Partner Provider may act as an independent controller for its own purposes. Its Processing is governed by its own documents and applicable law.

9. International Data Transfers

The Platform serves international Projects, so data may be stored and processed in Brazil and other countries where Users, Merchants, Partner Providers, or technical contractors are located.

For international transfers, PayHot uses mechanisms and contractual safeguards provided by law, including standard contractual clauses and requirements concerning confidentiality, security, and purpose limitation. Only the data necessary for the relevant purpose is transferred.

10. Retention

Data is retained no longer than necessary for the purposes of Processing, contract performance, dispute resolution, compliance with Partner requirements, and applicable retention periods. The period depends on the data category, transaction type, and legal requirements.

  • Account data is retained for the lifetime of the Account and a reasonable period after it is closed;
  • transaction and settlement data is retained for the period necessary for reconciliation, refunds, disputes, audits, and legal obligations;
  • review materials and risk assessments are retained during the relationship and after it ends within applicable periods;
  • security logs are retained for the period necessary to prevent attacks and investigate incidents;
  • data processed based on consent is retained until consent is withdrawn or the relevant purpose is achieved.

At the end of the retention period, data is deleted, anonymised, or isolated unless further retention is required by law or necessary to protect rights.

11. Security Measures

PayHot applies organisational and technical measures appropriate to the nature of the data and Processing risks. They may include access controls, multi-factor confirmation for certain actions, logging, encrypted communication channels, backups, anomaly monitoring, API controls, vulnerability management, and internal incident response procedures.

Absolute security cannot be guaranteed. The User must protect passwords, API keys, devices, and communication channels and promptly report any suspected compromise.

12. User Rights

Subject to applicable law, a User may request:

  • confirmation of Processing and access to data;
  • correction of incomplete, inaccurate, or outdated data;
  • anonymisation, blocking, or deletion of data processed unlawfully;
  • data portability where provided by law;
  • information about recipients to whom data has been disclosed;
  • information about the option not to provide consent and the consequences of refusing it;
  • withdrawal of consent and deletion of data processed on that basis where there is no other basis for retention;
  • review of a decision made solely by automated Processing where provided by law;
  • objection to Processing based on legitimate interests, subject to legal limitations.

Requests must be sent to team@pay.hot. To protect data, PayHot may request proof of the applicant's identity or authority. Some requests may be restricted where retention is required to perform a contract, prevent fraud, comply with law, or protect third-party rights.

13. Children's Data

The Platform is intended for adults and business representatives. PayHot does not knowingly request minors to register as Merchants. If PayHot becomes aware that a child or adolescent's data is being unlawfully processed, it will take measures in accordance with applicable law and the interests of that person.

14. Security Incidents

When an incident is identified, PayHot assesses its nature, possible consequences, and whether Users, Partners, and competent authorities must be notified. Notice is provided in the manner and within the period required by applicable rules where the incident may create a relevant risk or damage.

15. Cookies and Similar Technologies

The PayHot Website and interfaces use cookies and similar technologies for authentication, security, settings preservation, analytics, and improvements. Detailed terms are set out in the Cookie Policy. Optional cookies are used in accordance with the User's settings and applicable consent requirements.

16. Changes to the Policy

PayHot may update this Policy when laws, the Platform structure, technologies, or the Partner model change. A new version is published on the Website with its effective date. Additional notice may be provided for material changes.

17. Governing Law and Regulatory Framework

This Policy has been prepared with regard to the laws of the Federative Republic of Brazil, including the Brazilian General Personal Data Protection Law (LGPD), Law No. 13,709/2018, the Brazilian Civil Rights Framework for the Internet, Law No. 12,965/2014, and regulations and guidance of the Brazilian National Data Protection Authority (ANPD), as well as mandatory requirements of other jurisdictions where they apply to particular Processing.

18. Contact Details

HOT GATE TECHNOLOGY LTDA

CNPJ: 67.633.679/0001-27

NIRE: 33.2.1494553-4

Address: Avenida Marechal Câmara, 160, Sala 1107, Centro, Rio de Janeiro, RJ, CEP 20.020-907, Brazil

Email: team@pay.hot

Website: https://pay.hot