The EU General Data Protection Regulation (GDPR) replaces the Data Protection Directive 95/46/EC and was designed to harmonize data privacy laws across Europe, to protect and empower all EU citizens’ data privacy, and to reshape the way organizations across the region approach data privacy.
Key articles of the GDPR and information on its business impact can be found here.
This page contains a brief overview of key features and processes we have implemented to support GDPR compliance.
This brief overview illustrates our standard operating procedures around some key components of the GDPR regulation that we feel will be most applicable to our customers and business partners.
Lawfulness of Processing
Requirement: MassPay will need to have a lawful reason to use your data. Lawfulness of Processing may be enacted via consent, via notice and/or via execution of a contract (e.g. becoming a customer or partner).
Remedy: MassPay has added the ability to track and audit the grant of Lawfulness of Processing within our CRM and Marketing platform. Effective 1 January 2023, all new records created will be in compliance with this requirement. If your record was created prior to 1 January 2023, we will make a best effort to provide you with this information.
MassPay will only process personal data through AI Tools where it has a lawful basis to do so. Depending on the circumstances, the lawful basis may include performance of a contract, compliance with a legal obligation, legitimate interests, consent, or another lawful basis permitted by applicable data-protection law. Where MassPay relies on legitimate interests, it will consider the nature of the AI processing, the categories of personal data involved, the reasonable expectations of the data subject, the potential impact on the data subject, and appropriate safeguards.
Artificial Intelligence and Automated Processing
MassPay may use approved artificial intelligence, machine learning, automated analysis, or similar technologies (“AI Tools”) to support our services and business operations. AI Tools may be used for identity and document review, fraud prevention, account-matching support, transaction monitoring, KYB and onboarding support, periodic review support, customer support, operational analysis, financial reconciliation support, data summarization, document or contract review, translation, internal reporting, sales and marketing drafting, and other business, compliance, security, and productivity purposes.
Depending on the context, AI Tools may process names, email addresses, uploaded documents, transaction data, account activity, operational logs, company information, customer or prospect information, prompts, AI-generated outputs, summaries, alerts, risk indicators, usage logs, audit logs, and related metadata.
Consent
Requirement: MassPay shall be able to demonstrate that you have consented to the processing of your information for business communications.
Remedy: MassPay has defined processes for the ability to respond to requests for consent verification. Effective 1 January 2023, all new records created will be in compliance with this requirement. If your record was created prior to 1 January 2023, we will make a best effort to provide you with this information.
Automated Decision-making, Profiling and Human Review
MassPay may use AI Tools to assist human reviewers by identifying potential discrepancies, fraud indicators, transaction trends, account-risk issues, KYB review items, escalation items, or other operational matters. In most cases, AI outputs are advisory and are reviewed by authorized MassPay personnel before any material customer-facing action is taken.
MassPay does not intend to make decisions based solely on automated processing, including profiling, that produce legal effects concerning a data subject or similarly significantly affect a data subject, unless permitted by applicable law and subject to required safeguards. Where such processing occurs, MassPay will provide information required by law, implement appropriate safeguards, and provide applicable rights, which may include the right to obtain human intervention, express a point of view, contest the decision, and request meaningful information about the logic involved and the significance and envisaged consequences of the processing.
Withdrawal of Consent (Opt-Out)
Requirement: MassPay shall be able to illustrate which communications you have provided consent to receive and provide the ability for this consent to be withdrawn upon your request.
Remedy: MassPay has defined processes for the ability to Opt-Out of business communications in part or in total.
Rectification
Requirement: MassPay shall be able to provide you with verification of any incomplete or inaccurate personal data upon request.
Remedy: MassPay has defined processes for rectifying incomplete or inaccurate personal data, upon request.
Access & Portability
Requirement: MassPay shall be able to provide you with the personal data you have provided to MassPay in a structured, commonly used and machine-readable format.
Remedy: MassPay has defined processes for providing individuals with the personal data they have provided to our company in a structured, commonly used and machine-readable format.
AI Records, Access, Correction and Erasure
Personal data processed through AI Tools may appear in prompts, uploaded files, extracted text, AI-generated outputs, summaries, alerts, review notes, usage logs, audit logs, and related metadata. Data subjects may request access to, rectification of, erasure of, restriction of, portability of, or objection to personal data contained in AI-related records, subject to applicable legal limitations, retention obligations, security requirements, and the rights and freedoms of others.
Right To Be Forgotten
Requirement: MassPay shall be able to permanently delete all personal data the company has about you including, but not limited to, emails, call records, support ticket submissions, etc.
Remedy: MassPay has defined processes for permanently deleting all personal data the company has about an individual including, but not limited to, emails, call records, support ticket submissions, etc.
However, certain personal data may be retained if such data is required for execution of the contract between the individual, the individual’s company and MassPay or if the information is required by state, federal or international governing laws that supersede a RightTo Be Forgotten request.
Children’s Privacy
Our services are not intended for children. Where we process children’s personal data, we apply specific protections: if we rely on consent for an online service offered directly to a child, we obtain and record parental/guardian authorization for users below the applicable Member State digital-consent age (13–16; default 16) and use reasonable age-assurance. We minimize collection, disable targeted advertising and unnecessary profiling, set high-privacy defaults, keep data for the shortest necessary period, and complete a DPIA. Children—and verified parents/guardians—may exercise GDPR rights (access, rectification, erasure, restriction, portability, objection) by contacting compliance@masspay.io. We will promptly delete any children’s data collected without proper authorization.
AI Vendors, Transfers, Retention and Safeguards
MassPay may use third-party AI vendors and related service providers to process personal data on MassPay’s behalf. These providers may process personal data to provide AI functionality, maintain security, detect abuse, troubleshoot issues, support compliance, and enforce applicable terms. MassPay requires service providers to process personal data only for authorized purposes and in accordance with applicable contractual, confidentiality, security, and data-protection obligations.
MassPay does not authorize AI vendors or service providers to use customer personal data, uploaded documents, prompts, outputs, logs, confidential business information, or regulated financial information to train public or general-purpose AI models unless MassPay has provided appropriate notice and obtained any required authorization.
Some AI vendors and service providers may process personal data outside the European Economic Area, the United Kingdom, or the data subject’s country of residence. Where required, MassPay uses appropriate transfer mechanisms and safeguards, such as standard contractual clauses, data-processing agreements, vendor due diligence, access controls, and other technical and organizational measures.
MassPay may retain AI prompts, uploaded documents, AI-generated outputs, summaries, analysis, alerts, risk indicators, audit logs, usage logs, and related metadata as part of ordinary business records. Retention periods vary depending on the purpose of processing, the type of record, vendor settings, contractual commitments, legal and regulatory obligations, security needs, and MassPay’s retention practices.
MassPay applies safeguards designed to protect personal data processed through AI Tools. These may include approved-tool requirements, role-based access controls, single sign-on, multi-factor authentication, encryption where available, vendor due diligence, contractual data-protection requirements, usage monitoring, audit logs, data minimization, prompt and output controls, human oversight, accuracy review, incident response, and review before relying on AI-generated outputs for material decisions.
Where required by applicable law, MassPay will assess AI processing through data protection impact assessments, risk assessments, vendor reviews, records of processing activities, or other governance processes.
Questions
If you have questions regarding MassPay’s GDPR Policy or Procedures, please contact us at compliance@masspay.io.



Stop settling for generic platforms. Let's build a custom payout solution that scales worldwide, evolves with your business, and puts your people first - wherever they are.