PAYMESE BACK TO HOME
PRIVACY NOTICE

How PAYMESE handles information

ICSP OÜ, registry code 16454909, is the controller for the PAYMESE website and marketplace during this release. This notice applies to public browsing, account profiles, listings, enquiries, deal rooms, verification results, decisions, invoices and support communication.

Information we collect

We process signed-in identity data, business and authority details, listing and enquiry content, deal-room terms and decisions, external verification method, result, source reference, review dates and audit history, versioned account acceptances, invoice and payment-status information, security events and technical logs. New passport, ID-card, selfie and other customer-document uploads are disabled. Any files from an earlier release remain restricted until removed. Public teasers exclude the private company and contact fields.

Why we use it

We use information to create and secure accounts, review anonymous listings, qualify enquiries, operate controlled introductions, preserve accepted term versions, record external checks and manage invoices, prevent misuse, respond to requests and meet accounting, claims, sanctions or other legal obligations. The legal basis depends on the activity and may be steps requested before a contract, performance of a contract, legitimate interests in operating a secure business marketplace, consent where requested, or compliance with law.

Controlled disclosure

PAYMESE does not publish account contact details. For a new introduction, both participants must have current identity and business checks, current account terms and acceptances of the same deal terms for their current company profiles. PAYMESE then authorises contact release. Identity verification and new due-diligence documents are handled separately outside this website; an external checker has its own applicable privacy notice and retention policy, which must be made available before documents are provided. Files from an earlier release retain their separate access controls. Service providers supporting hosting, storage, email, verification, accounting or professional advice receive only the information needed for their work.

International processing

A cross-border marketplace may involve providers or counterparties outside the EEA. Where GDPR transfer restrictions apply, PAYMESE uses an available lawful transfer mechanism and proportionate safeguards. A participant’s information is not released to a proposed counterparty merely because that person submits an enquiry.

Retention and security

Records are retained for the period needed to operate the account or deal and for applicable accounting, legal-claim, fraud-prevention and regulatory periods. The verification record contains the result and reference, rather than a new identity-document image or biometric template. Historical files remain restricted to authorised users and can be removed from the room; a legal hold or mandatory retention duty may delay deletion. PAYMESE uses access controls, private storage, versioned acceptances, audit events and controlled document permissions, while no internet service can promise absolute security.

Your rights and contact

Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection and may complain to the Estonian Data Protection Inspectorate or another competent authority. Submit a privacy request through your secure PAYMESE workspace or by written correspondence to the registered address below. We may need to verify identity and authority before acting.

ICSP OÜRegistry code 16454909 · VAT EE102471854Treiali tee 2-3, Peetri alevik, Rae vald, Harju maakond 75312, EstoniaVersion 2026-09-15