PRIVACY POLICY

SONATA PAYMENTS SOLUTIONS FZE

License No. L-4739 | Payment Services Provider | Dubai World Trade Centre (DWTC), Emirate of Dubai, United Arab Emirates

Last updated: 28.08.2026

1. Introduction

SONATA PAYMENTS SOLUTIONS FZE (“Company”, “we”, “us”, or “our”) is committed to protecting the privacy and security of Personal Data processed in connection with the provision of its payment services. This Privacy Policy explains how we collect, use, store, disclose, and protect Personal Data, and describes the rights available to data subjects, in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”), its executive regulations, and other Applicable Law.

This Privacy Policy applies to Personal Data of Clients, prospective Clients, Merchants, UBOs, authorized representatives, and end payers/payees whose data is processed in connection with the Services, as well as visitors to our website and application.

2. Definitions

Term Definition
Controller the entity that determines the purposes and means of the Processing of Personal Data.
Data Subject an identified or identifiable natural person to whom Personal Data relates.
Personal Data any data relating to an identified or identifiable natural person, whether processed wholly or partly through electronic means.
Processing any operation performed on Personal Data, including collection, recording, storage, use, disclosure, transfer, or erasure.
Processor the entity that processes Personal Data on behalf of, and under the instructions of, the Controller.
Sensitive Personal Data Personal Data revealing racial or ethnic origin, religious or political beliefs, criminal record, biometric or genetic data, health data, or data relating to a person’s sexual life.

3. Data We Collect

3.1. We may collect and Process the following categories of Personal Data:

  • Identification data: full name, date of birth, nationality, passport/Emirates ID/national ID number, photograph, signature;
  • Contact data: address, email address, telephone number;
  • Corporate/KYB data: company name, registration number, UBO details, directors and authorized signatories, business activity, source of funds and wealth;
  • Financial data: bank account details, Payment Instrument details, transaction history, balances;
  • Technical data: IP address, device identifiers, browser type, log data, cookies and similar technologies (see our Cookie Policy);
  • Compliance data: sanctions and PEP screening results, risk-scoring data, correspondence relating to due diligence.

3.2. We do not intentionally collect Sensitive Personal Data unless strictly necessary for compliance purposes and permitted under the PDPL, and only with appropriate safeguards.

4. Purposes and Legal Bases of Processing

Purpose Legal Basis
Onboarding, KYC/KYB verification, and Account creation Performance of a contract; compliance with a legal obligation
Processing Transactions and providing the Services Performance of a contract
AML/CFT screening, transaction monitoring, and reporting to authorities Compliance with a legal obligation
Fraud prevention and security Legitimate interest; compliance with a legal obligation
Customer support and communication Performance of a contract; consent
Marketing communications Consent (may be withdrawn at any time)
Legal claims and regulatory audits Compliance with a legal obligation; legitimate interest

5. Consent

5.1. Where Processing is based on consent, such consent will be obtained in a clear, specific, and unambiguous manner, and the Data Subject may withdraw consent at any time by contacting us at the details set out in Section 13, without affecting the lawfulness of Processing carried out prior to withdrawal.

5.2. We will provide the Data Subject with clear information about the purpose of Processing and any third parties with whom Personal Data will be shared prior to obtaining consent, where consent is the applicable legal basis.

6. Disclosure of Personal Data

6.1. We may disclose Personal Data to: banks, payment systems, card schemes, and payment aggregators engaged to provide the Services; regulatory and governmental authorities, including the UAE Financial Intelligence Unit, where required by Applicable Law; professional advisors bound by confidentiality obligations; IT and cloud service providers acting as Processors under written data processing agreements; and any successor entity in connection with a merger, acquisition, or transfer of business.

6.2. We do not sell Personal Data to third parties for their own independent marketing purposes.

7. Cross-Border Data Transfers

7.1. Personal Data may be transferred to, and processed in, countries other than the UAE, including countries where our Processors or Service Providers are located. Any such transfer shall be carried out in accordance with Articles 22-23 of the PDPL, including, where required, through adequacy determinations, appropriate contractual safeguards (such as standard data protection clauses), or other mechanisms recognized under Applicable Law.

8. Data Retention

8.1. We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. In particular, KYC/AML records and transaction records shall be retained for a minimum of five (5) years following the end of the business relationship or the date of the transaction, whichever is later, in accordance with UAE AML/CFT legislation, or such longer period as required by Applicable Law.

8.2. Upon expiry of the applicable retention period, Personal Data shall be securely deleted or anonymized.

9. Data Security

9.1. We implement technical and organizational measures appropriate to the risk, including encryption of data in transit and at rest, access controls, network security monitoring, staff confidentiality obligations and training, and regular testing and evaluation of security measures, in accordance with Article 20 of the PDPL.

9.2. In the event of a Personal Data breach that is likely to prejudice the privacy, confidentiality, or security of Personal Data, we shall notify the UAE Data Office without undue delay, and shall notify affected Data Subjects where the breach is likely to adversely affect their Personal Data or privacy, in accordance with Article 9 of the PDPL.

10. Data Subject Rights

10.1. Subject to the exceptions and conditions set out in the PDPL, Data Subjects have the right to: obtain confirmation of, and access to, their Personal Data; request correction of inaccurate Personal Data; request erasure of Personal Data; restrict or object to Processing, including for direct marketing purposes; request data portability, where technically feasible; and withdraw consent at any time where Processing is based on consent.

10.2. Requests to exercise these rights may be submitted to the Company using the contact details in Section 13. We will respond within the timeframe required by Applicable Law.

11. Data Protection Officer

11.1. Where required under Article 10 of the PDPL, the Company shall appoint a Data Protection Officer (“DPO”) responsible for overseeing compliance with this Privacy Policy and Applicable Law. Contact details of the DPO, where appointed, are set out in Section 13.

12. Children’s Data

12.1. The Services are not directed to individuals under the age of eighteen (18), and we do not knowingly collect Personal Data from minors. If we become aware that we have inadvertently collected Personal Data from a minor without appropriate consent, we will take steps to delete such data.

13. Contact Us

For questions, requests, or complaints regarding this Privacy Policy or the Processing of your Personal Data, please contact us at:

SONATA PAYMENTS SOLUTIONS FZE
Office 4.07-COW5-135, Sheikh Rashid Tower, Dubai World Trade Centre, Dubai, United Arab Emirates
Email: info@sonatapayment.com

14. Changes to this Privacy Policy

14.1. We may update this Privacy Policy from time to time to reflect changes in our practices or Applicable Law. The updated version will be published on our website with a revised “Last updated” date. Material changes will be notified to Clients through the Services or by email, where appropriate.