lock Legal

Privacy Policy

What personal data DORSKO LIMITED collects through DorskoPay, why, who receives it, how long it is kept, and the rights you have over it.

Version 1.0 · Effective 20 August 2026 · Last updated 20 August 2026
Current status: DorskoPay is not processing production card transactions today. Sections describing production payment processing set out how personal data is designed to flow once an acquiring partner has approved DorskoPay; they are marked where that distinction matters. Everything else describes processing that happens now.

The short version

  • check DORSKO LIMITED is the controller for the data described here.
  • check We collect what is needed to run an account, complete a purchase, calculate tax, verify a seller, prevent fraud and meet our legal obligations — and not more.
  • check We do not sell personal data, and we do not run advertising or cross-site tracking.
  • check We do not store full card numbers or card security codes. Payment credentials sit with the payment partner and we hold only a token, the brand, the last four digits and the expiry.
  • check You have rights of access, rectification, erasure, restriction, portability and objection, and you can complain to the ICO.

1. Who we are and how to contact us

DORSKO LIMITED, a company incorporated in England and Wales under company number 15104126, whose registered office is at Unit A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom, trading as DorskoPay, is the controller for the personal data described in this policy.

For any privacy question, or to exercise a right under clause 12, contact support@dorskopay.com with "Privacy" in the subject line, or write to the registered office above.

We have not appointed a statutory Data Protection Officer, because we are not required to appoint one. Privacy requests are handled by the company's management.

2. Whose data this policy covers

Buyers
People and businesses who purchase software through a DorskoPay checkout, payment link, or in-application purchase flow.
Suppliers
Software companies who hold a DorskoPay account to sell their products, together with their directors, ultimate beneficial owners and authorised representatives.
Website visitors
Anyone who browses dorskopay.com without creating an account or making a purchase.
People who contact us
Anyone who uses the contact form, emails support, or opens a support ticket.

A supplier is a controller in its own right for the customer data it holds inside its own product. This policy covers what DorskoPay does, not what a supplier does with data in its own systems.

3. Our role: controller, and where we are a processor

Under the Merchant of Record model, DorskoPay is the seller of record on the transaction. It follows that DorskoPay is an independent controller — not a processor acting on a supplier's instructions — for the personal data it processes in order to sell, invoice, tax, refund and defend that transaction. Those are DorskoPay's own legal obligations, and a supplier cannot instruct us out of them.

DorskoPay is also an independent controller for supplier account data, verification and financial-crime data, security logging, and its own accounting records.

Where DorskoPay hosts data on a supplier's behalf that is not part of the sale — for example a supplier's own customer list, imported into the dashboard for the supplier's purposes — DorskoPay acts as a processor for that data. The Supplier Agreement and the data processing terms referenced in it govern that relationship.

This split is deliberate and is set out honestly. A platform that claims to be only a processor while also being the seller of record, the taxpayer and the party defending chargebacks is describing a relationship it does not have.

4. What we collect, why, and on what legal basis

The table below is built from the actual data model of the application. Legal bases are stated under UK GDPR.

Category What it includes Why Legal basis
Buyer identity and contact data Name, email address, billing address, country. To complete the purchase, deliver the product, issue the receipt and provide support. Performance of a contract; legal obligation for the tax and accounting records.
Supplier account data Name, email, password hash, trading name, website, product description, business type, expected volume, target regions, notification and language preferences. To create and operate the supplier account and the dashboard. Performance of a contract.
Corporate verification (KYB) data Legal entity name, company registration number, tax identification number, registered address, country, account type. To verify who we would be contracting with and reselling for, and to meet payment-partner onboarding requirements. Legal obligation and legitimate interests in preventing financial crime; necessary for the contract.
Director and beneficial owner data Name, role, country of residence, nationality, residential address, and — where identity verification is run — the identity document and verification outcome. To verify ownership and control of a supplier business as part of onboarding and periodic review. Legal obligation and legitimate interests in preventing financial crime.
Transaction and order data Transaction reference, product, price, currency, gross amount, tax amount, tax rate and tax name, commission, net amount, discount applied, status, country, order grouping, and any buyer VAT number supplied at checkout. To process and record the sale, calculate tax, produce documentation, calculate supplier proceeds, and handle refunds and disputes. Performance of a contract; legal obligation for tax and accounting.
Payment metadata Payment gateway name, gateway reference, payment method token, card brand, last four digits, expiry month and year, and the cardholder name as typed at checkout. To take the payment, charge a subscription renewal, issue a refund and defend a dispute. Performance of a contract; legitimate interests in fraud prevention.
Fraud and risk data IP address captured at checkout, a coarse device fingerprint hash, risk flags raised on a transaction or account, and the outcome of any manual review. To detect card testing, velocity abuse and refund abuse, and to meet payment-partner and card-scheme risk obligations. Legitimate interests in preventing fraud and protecting the platform, its buyers and its suppliers.
Security and access logs Every sign-in attempt with the email attempted, IP address, user agent, outcome and timestamp; administrative actions taken in the admin panel; API request method, path, status code and timestamp. To detect and investigate unauthorised access, to support incident response, and to provide an audit trail. Legitimate interests in the security of the platform; legal obligation where an incident is reportable.
Support and communications data Support tickets and their messages, contact form submissions, and the correspondence attached to a refund or dispute investigation. To answer the enquiry, resolve the problem, and keep a record of what was decided. Performance of a contract, or legitimate interests in responding to an enquiry.
Abandoned checkout data Email address and name entered at a checkout that was not completed, with the product and the time last seen. To send a single reminder that a purchase was not completed, at the supplier's configuration. Legitimate interests in completing a transaction the person had started; objection under clause 12 stops it.
Payout and banking data Account holder name, sort code, account number and payout currency for a supplier. To pay a supplier its proceeds, and to verify that the payout account belongs to the verified business. Performance of a contract; legal obligation and legitimate interests in preventing financial crime.
Preference and consent data Language preference, notification preferences, and the record of consents given at checkout under clause 5. To honour your preferences and to evidence a consent that the law requires us to be able to prove. Performance of a contract; legal obligation to demonstrate consent where consent is the basis.
We do not collect special category data, and we do not ask for it. Where an identity verification provider processes an identity document, any biometric processing is carried out by that provider under its own terms and with the explicit consent it collects; DorskoPay receives the outcome of the check and the document reference, not a biometric template.

5. Consent records we keep

Where the law requires us to be able to prove that you agreed to something, we keep a record of it. For each such consent we store: what exactly you were shown, the version of the document in force, the moment you gave it, the order or account it relates to, and — where it is relevant to proving the consent — the IP address it came from.

  • Acceptance of the Buyer Terms at checkout, with the version accepted.
  • Authorisation of a recurring payment, with the amount, currency and billing schedule authorised.
  • Express consent to immediate supply of digital content, and the acknowledgement of the effect on cancellation rights, where that consent is given.
  • Cookie preferences, where a non-essential cookie is ever introduced.
  • Marketing consent, if it is ever collected.

These records exist to protect you as much as us: they are the evidence that a renewal was disclosed, or that a cancellation right was or was not validly waived. They are retained for as long as the underlying transaction record, under clause 10.

6. Where the data comes from

  • Directly from you — at checkout, in the sign-up and onboarding forms, in your account settings, and in anything you send to support.
  • From your use of the platform — logs, transaction records, IP address and device signals generated automatically as you use it.
  • From a supplier — where a supplier creates an order or a customer record through the API for a buyer it already has.
  • From an identity verification provider — the outcome of a verification check on a director or beneficial owner, where such a check is run.
  • From a payment partner — the outcome of an authorisation, a settlement record, or notification of a dispute.
  • From public sources — a company register, a sanctions list, or a supplier's own public website, when we verify or monitor a supplier.

7. What we do with it

What happens today

Creating and operating accounts; running the sandbox checkout and the simulated transactions in it; calculating and displaying transaction tax; verifying sellers and their directors; screening for fraud and unauthorised account access; sending transactional email; providing support; producing the platform's own analytics; and meeting our accounting, tax and record-keeping obligations.

What is designed to happen for approved production transactions

For production transactions, once an acquiring partner has approved DorskoPay, the same data is additionally used to authorise and capture card payments, to settle them, to schedule and execute supplier payouts, to issue buyer-facing tax documentation under DorskoPay as seller of record, and to defend chargebacks with the acquirer and the card schemes.

What we never do

  • We do not sell personal data.
  • We do not share personal data with advertising networks or data brokers.
  • We do not run cross-site tracking or behavioural advertising.
  • We do not use your data to train machine learning models offered to third parties.
  • We do not make solely automated decisions producing legal or similarly significant effects about you without a route to human review — see clause 9.

8. Who we share it with

We share personal data with the categories of recipient below, each of which receives only what it needs for its function.

Recipient What they receive Status
Hosting and database provider All platform data, as the infrastructure it runs on. In use today. Processor.
Transactional email provider Recipient email address and message content, when email delivery is configured for live sending. In use when configured; the application defaults to writing mail to a local log instead.
Payment and acquiring partners Cardholder and transaction data needed to authorise, capture, settle, refund and dispute a payment. Designed dependency. No acquiring partner has approved DorskoPay for production at the date of this policy. Independent controllers for their own regulatory purposes.
Identity verification provider Director or beneficial owner identity data and the identity document, where a live verification check is run. Integrated but not enabled by default: the application ships with verification simulated and no provider credentials configured. Independent controller for its own regulatory purposes.
SMS provider Mobile number and one-time code, where SMS verification is configured for live sending. Integrated but not enabled by default; the application defaults to logging codes locally.
Suppliers The buyer name, email, country and order detail needed to fulfil and support the purchase. In use today. Independent controllers for fulfilment and support of their own product.
Address autocomplete provider Partial address text you type, and your IP address, where address autocomplete is enabled with an API key. Only active where an API key is configured; disabled otherwise, and the address fields work normally without it.
Web font provider Your IP address and browser information, when the page loads fonts. In use today on the public site.
Professional advisers Records relevant to a specific matter — accountants, auditors, insurers or lawyers. As needed.
Authorities and regulators What we are legally required to disclose, or what is necessary to establish, exercise or defend legal claims. On lawful request only.

If DORSKO LIMITED is sold, merged or reorganised, personal data may transfer to the acquiring entity, which would be bound by this policy until it lawfully replaces it. We would tell you before that happened.

We do not name individual vendors in this policy because the list changes and a stale name is worse than a clear category. The current named list is maintained in our internal vendor register and is available on request under clause 12, and to a payment partner or auditor on request.

9. Automated processing and fraud screening

We run automated checks on transactions and accounts — velocity checks, device and IP signals, and pattern checks that flag card testing and refund abuse. These can cause a transaction to be held for review, or an account to be suspended pending investigation.

Where an automated check would produce a legal or similarly significant effect — declining a purchase outright, or suspending an account — a human reviews the outcome before it becomes final, or on request immediately afterwards. You can ask for that review, put your side of it, and receive a decision from a person, by contacting support@dorskopay.com.

We do not publish the specific rules or thresholds these checks use, because publishing them would tell the people we are screening for exactly how to pass. This does not limit your right to a human review of a decision that affects you.

10. How long we keep it

We keep personal data only as long as we need it for the purpose it was collected for, or for as long as a legal obligation requires. The retention framework below is what governs it; the full internal matrix sits in our data retention policy.

Data Retained for Why
Transaction, order, invoice and tax records The period required by UK accounting and tax law, running from the end of the relevant accounting period. Statutory record-keeping. This period is fixed by law and cannot be shortened by an erasure request.
Supplier account and contract records For the life of the relationship, and then for the period required after it ends for financial-crime record keeping and to resolve claims. Contract, financial-crime record keeping, limitation periods.
KYB, director and beneficial owner verification records For the life of the relationship and the retention period applicable to financial-crime records afterwards. Financial-crime record keeping and payment-partner requirements.
Buyer account data While the account is active, and then until the associated transaction records reach the end of their own retention period. Contract, and the statutory life of the transaction record.
Payment method tokens Until the payment method is removed, the subscription ends, or the account closes. Contract.
Dispute and chargeback records For the period required by the card schemes and payment partners after the dispute closes, and no less than the transaction record it relates to. Scheme rules and defence of claims.
Fraud and risk review records For as long as needed to operate the control and to demonstrate the decision, then deleted or aggregated. Legitimate interests, and demonstrating our controls to a payment partner.
Security and sign-in logs A rolling period appropriate to detecting and investigating intrusions. Security.
API request logs A rolling operational period. Debugging, abuse detection and support.
Support tickets and correspondence For as long as needed to resolve the matter and to handle a related complaint or claim. Contract and defence of claims.
Abandoned checkout records A short period sufficient to send one reminder and to reconcile against a completed purchase. Legitimate interests.
Consent records For as long as the transaction or relationship they evidence. Demonstrating consent where the law requires it.

Where a record must be kept for a statutory period, we restrict it rather than delete it on request: it stays for the legal purpose and is not used for anything else.

11. International transfers

Personal data is processed primarily in the United Kingdom and the European Economic Area. Some recipients described in clause 8 process data outside the UK.

Where personal data is transferred outside the UK, we rely on one of: a UK adequacy determination for the destination country; the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum; or another lawful transfer mechanism. Where the mechanism requires it, we carry out a transfer risk assessment.

You can ask us which mechanism applies to a specific transfer, and request a copy of the relevant safeguards, using the contact route in clause 12.

12. Your rights

Under UK GDPR, and subject to its conditions and exemptions, you have the right to:

  • be informed — this policy, and any more specific notice we give you;
  • access the personal data we hold about you, and receive a copy;
  • rectification of data that is inaccurate or incomplete;
  • erasure, where we no longer have a lawful reason to keep it;
  • restriction of processing, in defined circumstances;
  • data portability, for data you provided to us that we process by automated means on the basis of consent or contract;
  • object to processing based on legitimate interests, including the abandoned-checkout reminder in clause 4;
  • withdraw consent at any time where processing is based on consent, without affecting the lawfulness of what was done before;
  • not be subject to a solely automated decision with legal or similarly significant effects — see clause 9.

To exercise a right, email support@dorskopay.com with "Privacy" in the subject line. We respond within one month, and will tell you if we need to extend that by up to two further months because the request is complex. We may need to verify your identity first, and will ask only for what is proportionate to do that.

There is no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse it — and if we refuse, we will explain why and tell you how to challenge it.

Erasure does not extend to records we are legally required to keep, such as transaction, invoice and tax records. We will tell you which records those are and confirm that they are restricted to that purpose.

13. Complaining to a regulator

If you are unhappy with how we have handled your personal data, please tell us first — most issues are resolved quickly, and the Complaints Policy sets out how we handle it.

You also have the right to complain at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection, at ico.org.uk. Complaining to us first is not a precondition.

If you are in the European Economic Area, you may also complain to the supervisory authority in your country of residence, place of work, or the place of the alleged infringement.

14. Security

We protect personal data with the technical and organisational measures described on the Security page, which separates controls implemented today from controls that depend on production infrastructure. Passwords are stored as hashes and never in a recoverable form; full card numbers and card security codes are never stored on our systems.

No system is perfectly secure. Where a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it where the law requires, and will notify you directly where the risk to you is high.

15. Cookies and browser storage

The cookies the site actually sets — all of them, with names, purposes and durations — are listed in the Cookie Policy. We do not run advertising, analytics or cross-site tracking cookies.

16. Children

DorskoPay is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

17. Changes to this policy

We update this policy when our processing changes. The version number and effective date at the top of this page tell you which version you are reading.

Where a change is material, we will bring it to your attention — by email to account holders, or by a notice on the site — before it takes effect.

Related documents

DORSKO LIMITED trading as DorskoPay · Company No 15104126 · Registered in England and Wales

Registered office: Unit A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE

support@dorskopay.com