NOTICE ON THE PROCESSING OF YOUR PERSONAL DATA THROUGH THE “PAYZY BY COSMOTE” APPLICATION (Data Privacy Notice)
1. Introduction
The societe anonyme under the name COSMOTE Payments - ELECTRONIC MONEY SERVICES SINGLE MEMBER SOCIETE ANONYME, which has its registered office in Maroussi, Attica (99, Kifissias Avenue), (hereinafter COSMOTE Payments or COMPANY) considers the protection of your personal data particularly important and complies with the principle of transparency regarding their processing. If you wish to be informed in general about the processing of your personal data by COSMOTE Payments, please read the text of the General Information regarding the Protection of your Personal Data, which you can find here.
Through the “payzy by COSMOTE” application (hereinafter the “Application”), various services are provided (hereinafter the “Services”), which are described in detail in the corresponding text of Terms and Conditions of Use of the Application. Prerequisite for the use of the Application is the registration of the User in the Application for the provision of electronic money and payment services, which is provided by COSMOTE Payments and the authentication of the User by it.
With this text, we would like to inform you on the processing of your personal data during the use of the Application and the Services.
These terms constitute part of the Terms and Conditions of Use of the ‘payzy by COSMOTE’ Application and must always be interpreted in conjunction with them and form a single whole.
If the use of a Service, which is provided through the Application, is regulated by separate terms regarding the processing of personal data, the latter shall be considered as a whole with these terms but shall take precedence over them if they regulate differently the same issue.
2. What are the identity and contact details of the personal data controller?
Personal data controller is COSMOTE Payments, which you can contact by email at customerprivacy@cosmotepayments.gr or by mail, sending a letter to “COSMOTE Payments ELECTRONIC MONEY SERVICES SINGLE MEMBER SOCIETE ANONYME”, Maroussi, Attica (99, Kifissias Avenue).
3. What categories of personal data do we collect and process during the use of the Application and the Services and for which purpose
3.1 For your registration and use of the Application, as well as for the use of the Services provided through it, we process your personal data with the purpose of execution of the agreement between us (Article 6(b) of GDPR), and specifically:
3.1.1 For the User Registration in the App, the following are used:
a. email address and mobile phone number, and
b. the full name, date and place of birth, residential address, professional activity, tax data (TIN/Tax Office), the number and details of the identification document (identity card/passport), or
c. the taxisnet codes, so that the data mentioned in b. can be obtained from the state Digital Portal,
and documents certifying the above are collected on a case-by-case basis, such as the identification document (identity card/passport), tax clearance certificate (E1) and certificate of occupation and residence.
In order to achieve the electronic remote identification of your data, COSMOTE Payments may process, if you consent, data concerning:
• the recording of your visual and audio communication with our representative in real time via video call.
• the biometric characteristics resulting from the recording of your dynamic-selfie, to carry out a check, in relation to the photo of the identification document, using special software without the presence of our representative. In case that you do not consent to the use of biometric data, electronic remote identification is carried out via a video call with a representative.
Read the text with which the relevant consent is provided here .
3.1.2 For the execution of transactions through the “Wallet” service (e.g., cash in/cash out of payment account, the execution of card transactions, the display of balance of payments and the display of history of transactions, the Application shall process the following data:
• Details such as number of individual payment account at COSMOTE Payments, bank account number (IBAN) at COSMOTE Payments and/or with a Third bank, time, beneficiary, transaction amount, means of payment.
• Details of payment cards for cash-in/cash-out of the payment account.
• Details of payment cards for their use as means of payment on the Application.
3.1.3 For the use of Chat & Pay Messages Exchange Service (hereinafter “Chat & Pay”) and specifically the communication between Users of the Application and the transfer of electronic money from the Payment Account of a User of the Application to the Payment Account of another User of the Application (credit):
Data for the operation of Chat & Pay: Full name, e-mail address, mobile phone number, profile photograph, nickname, Payment Account Number (IBAN), User dialogues at COSMOTE Payments.
3.1.4 For your participation in the “Coins” Loyalty Program: :
Number of your personal debit card which has been provided to you by COSMOTE Payments, history of payments you have made using your personal debit card which has been provided to you by COSMOTE Payments, number of reward points you have collected, number and balance of Payment Account (IBAN) at COSMOTE Payments.
3.1.5 For the use of the Split It Expenses Sharing Service (“hereinafter Split It”): Data for your participation in a Split It Expenses Sharing Group:
• Full name, e-mail address, mobile phone number, profile photograph, nickname
• Data for the settlement of transactions in the context of your participation in a Split It Expenses Sharing Group: Payment Account Number (IBAN) at COSMOTE Payments
3.1.6 For the use of the “Piggys” Personal Safe Service (hereinafter “Piggys”): Payment Account Number (IBAN) at COSMOTE Payments, my Vault Payment Account Number at COSMOTE Payments, number of your personal debit card which has been provided to you by COSMOTE Payments, history of payments you have made using your personal debit card which has been provided to you by COSMOTE Payments
3.1.7 For the use of the “Cards” Card Issue and Use Service, and, more specifically, for the application for the issue and dispatch of payzy debit card, in plastic/physical or virtual form:
• Identity Card details, postal address, Payment Account Number (IBAN) at COSMOTE Payments
3.1.8 For the use of the Bill Payment Service by RF Single Payment Code: Payment Account Number (IBAN) at COSMOTE Payments, data of registered RF Single Payment Code
Moreover, aiming at your best service and the resolution of problems you might face while using the Services and the Application, we shall process: data resulting from the registration, activation and use of the Services and the Application, identity details, type, model and features of your device, connection details, details from your communication with us (e.g. contact telephone number and availability for your communication with a representative, recording of your conversation with our representative, detailed recording of the problem, etc.), transaction details, as well as other details that you disclose to us in order to investigate queries, complaints, challenges of charges, etc.
3.1.9 For the execution of transactions through the payzy pro Payment Service: Full name, Payment Account Number (IBAN) at COSMOTE Payments, nickname.
3.1.10 Moreover, for the purposes of reporting the cashbacks paid by the payzy pro businesses, we process: Payment Account Number (IBAN) at COSMOTE Payments, date and time of Transaction with cashback, cashback amount.
3.2 Based on your consent (Article 6(1) (a) of GDPR), we shall process your personal data with the purpose of providing specific functionalities of the Application. Specifically, based on your consent, we shall process:
3.2.1 Data with the purpose of your information on which of your contacts are holders of payment account at COSMOTE Payments: Data of your contracts on the terminal device on which the Application is installed. Provided that you have given your consent, the other users of the Application and holders of Payment Account at COSMOTE Payments will be able to search you in order to communicate with you through the Application. Based on your preference, there shall be three alternative choices based on which other users of the Application may search you. In any case, you will be able at any time to select the choice you wish through the Application at the settings of your account and specifically settings -> security settings -> who will be able to search for my profile?
• Available for search by all users of the Application: All users of the Application and holders of Payment Account at Cosmote Payments will be able to search you either by your full name or by e-mail, nickname, mobile phone number you have submitted during your registration and authentication at COSMOTE Payments.
• Available for search only by users of the Application who have the contact number you have submitted during your registration and authentication at COSMOTE Payments stored in the contact data of their terminal device: Only the users who, at the same time, have the contact telephone number you have submitted during your registration and authentication at COSMOTE Payments stored in the contact data of their terminal device will be able to search you, either by your full name or by e-mail, nickname, mobile phone number you have submitted during your registration and authentication at COSMOTE Payments.
• Not available for search: Your account shall remain hidden from all other users of the application and no user will be able to search you in order to communicate with you through the Application.
3.2.2 Data with the purpose of showing reviews in stores in which you have made a payzy pro payment: nickname, profile photograph and store review rating. The appearance of the review on the page of the payzy pro business, follows the user’s preference described in 3.2.1. More specifically, if the user has selected to be available for search by all other users, the review is visible to all, if the user has selected not to be available for search by anybody, the review will not be visible to anybody, and if the user has selected to be available for search by the users of the Application who have stored in the contact data of their terminal device the contact telephone number you have submitted during registration, the review is visible only to the users of the Application who, at the same time, have stored in the contact data of their terminal device the contact telephone number you have submitted upon your registration.
3.2.3 For your participation in the “Bring Along Friends” promotional action:
• Data for checking the conditions of your participation in the “Bring Along Friends” promotional action: full name, father’s name, mother’s name, identity card details, number, and statement of Account (IBAN) at COSMOTE Payments.
• Data resulting from the participation in individual promotional actions: history of participation, total reward amount, details of your success (e.g. list of friends registered in the application), number and balance of Payment Account (IBAN) at COSMOTE Payments
3.2.4 Moreover, we shall process the below mentioned data, for purposes related to the improvement of your experience during the use of the Application and the Services provided through it. Specifically:
• For the creation of an individual profile: data resulting from the registration, activation and use of the Services and the Application in order to create your individual profile based on your personal preferences. The creation of an individual profile is a form of automated processing of your above data, through which it is possible to assess some preferences of yours, such as suggest products that may interest you and send you relevant information / advertisements that respond to your interests. You may disable this processing from the settings of the Application and specifically settings -> terms of use and personal data -> individual profile and personalization -> individual profile. (legal basis is Article 6(1)(a) of GDPR — consent)
3.2.5 The application enables the storage of your payment card (debit / credit / prepaid), so that no new entry of the card is not required for each transaction. For the protection of payment cards data and for the security of transactions, a tokenization process of payment card numbers is applied. Payment card data are stored in a secure environment of COSMOTE Payments.
3.3 Based on our legitimate interest (Article 6(1) (f) of GDPR), we shall process your personal data with the purpose of:
Receipt of news and notifications: For direct marketing of our products and services, COSMOTE Payments may process a limited range of your Data, and those data included in your agreement, aggregated details of use and/or requests that you have submitted to us. Such processing shall be limited and shall aim exclusively to the submission of proposals, offers, news and notifications on related products and/or services. You have the right to object to communication from the settings of the Application and specifically settings -> terms of use and personal data -> individual profile and personalization -> news and notifications.
4. Trackers / Cookies
Cookies are small files stored on the user’s computer or mobile device and are placed by websites that they visit and/or mobile applications they use, in order to recognise them. In addition to cookies, there are other trackers, such as pixels (e.g. Facebook Pixel), local storage, third-party SDKs included in mobile applications, etc. Trackers store or acquire information or gain access to information which is stored in the user’s terminal equipment (computer, mobile phone, etc.). Such trackers are used for better operation and improvement of Yzy Bot, acquiring access to search details in Yzy Bot (question, tags, keywords, etc.), feedback details (e.g. navigation to service articles).
You can be informed on the categories of cookies / trackers we use and manage your choices through the application and specifically from the menu settings -> terms of use and personal data -> management of trackers.
5. Permissions of the Application
The operation of the Application and the provision of the Services through the Application presupposes the installation and use of the Application, which, depending on the operating system in which it is installed, may require, or request optional permission to the following data of your terminal device:
• Data of your contacts: with the purpose of your information on which of your contacts are also Users of the Application and holders of a Payment Account at COSMOTE Payments.
• Location data (GPS): with the purpose of indication of your location on the map and your information on offers in stores near you.
• Camera: Use of camera for the determination of your profile photograph, as well as of the profile photograph of the groups you create within the use of the Application (e.g. within the provision of the Split Bill” Service “).
• Storage space: Permission shall be required for the storage of PDFs of quarterly settlement statements regarding the transactions and payment acts of your Payment Account, including those through your Card, analyses, receipts of payment, for the alternative method of determination of your profile photograph, as well as for the alternative method of determination of profile photograph of the groups you create within the use of the Application (e.g. within the provision of the “Split Bill” Service).
• Internet: The application requires access to the Internet in order to communicate with the systems of COSMOTE Payments and display the information concerning you (e.g. connection details, account details and others).
6. Display of push notifications
The payzy by COSMOTE application sends notifications to your device in order for you to:
i. inform you or/and complete the transactions (e.g. for the execution of payment services),
ii. notify you on messages you receive through the Chat & Pay Service,
iii. receive promotional messages and news, provided that you have not requested to be exempted from them either upon registration or through the settings in section “Communication Settings”,
iv. receive personalized suggestions and offers based on your personal profile, provided that you have given your consent (section “Communication Settings”).

If you wish to opt out of receiving any notifications, you can change your selections in the device settings.
7. For how long do we retain your personal data?
If you delete your account from the Application, your data (e.g. interactions with other Users, chat discussions) will be deleted in a manner that their retriev al will not be technically feasible or they will be anonymized, within 90 days.
8. Will COSMOTE Payments process your personal data for other purposes as well?
COSMOTE Payments will not process your personal data for other purposes except for those mentioned above. In case COSMOTE Payments wishes to use your personal details for other purposes, it will do so only after you have been informed, and it has received your explicit consent.
9. Who are the recipients and why are personal data transferred to them?
Recipients of your personal data can be:
A. Third companies with which we are cooperating for the provision and support of the Application, as well as of the Services provided through it. Specifically:
• the company Cognity SA which supports the operation of the Application and has its registered office in Greece.
• the company OGILVY ONE WORDWIDE- ATHENS PROMOTION, ADVERTISING AND DIRECT MARKETING S.A, which provides advertising and supporting services and is based in Greece.
• NEXI GREECE PROCESSING SERVICES SOLE PROCESSING COMPANY, which provides payment processing and card issuing services and has its registered office in Greece.
• NETCOMPANY-INTRASOFT S.A., which provides and supports the operation of the banking systems of COSMOTE Payments and has its registered office in Greece.
In these cases, such third companies are processors on behalf of COSMOTE Payments, that is, partners of COSMOTE Payments who undertake the performance of a specific project following our instructions and applying the strict procedures of OTE Group regarding the processing of your personal data. In these cases, COSMOTE Payments shall continue to be responsible regarding the processing of your personal data.
The processing of your personal data for the above purposes by our partners shall be conducted mainly within Greece and the European Union (EU). In case we cooperate with companies outside the EU, they will process your data only by our order and if there is an adequacy decision of the European Commission or appropriate clauses that ensure high level of security in relation to the processing of your personal data are agreed.
Except for the abovementioned companies, COSMOTE Payments shall not process and shall not disclose your personal data to third parties except in the cases where their disclosure/transfer is imposed by the applicable legislation.
In the case of the processing purpose mentioned in 3.1.9 above, recipients of your personal data are:
Each payzy pro business to which you have executed payments.
10. What are your rights as user of the Service regarding the processing of your personal data?
The rights you can exercise include:
• Right of access: You have the right to be informed in relation to your personal data being processed by us (e.g. the purposes of processing, types of data, recipients to whom they are disclosed, the period for which they are retained) and to provide you with copies thereof.
• Right to rectification: You have the right to request the rectification of your data (e.g. correction of address, contact details).
• Right to erasure: You have the right to request the erasure of your personal data in case they are no longer necessary in relation to the purposes for which they were processed or in case you have withdrawn the basis on which we collected and processed them.
• Right to restriction of processing: You have the right to request the restriction of processing for a specific reason (e.g. I do not wish to receive notifications in my e-mail for marketing purposes).
• Right to data portability: You have the right to receive your personal data you have provided to the company, in a structured, commonly used format which has also a readable form.
• Right to object the processing of your personal data in the cases you do not wish the processing of your personal data.
In order to exercise your rights, you can:
a. send an email to customerprivacy@cosmotepayments.gr , or
b. a fax to +30 2102511888 or
c. a letter to the address COSMOTE Payments Customer Service, 99 Kifissias Avenue, 15124, Maroussi, with subject “Exercise of personal data rights”
accompanied by a copy of your identity card and indicating your full name and the connection number of your mobile or fixed-line phone.
In case you consider that we have not adequately satisfied your request and that the protection of your personal data is affected in any way, you can file a complaint through a special web portal to  the Hellenic Data Protection Authority (Athens, 1-3 Kifissias Avenue, PC 115 23 | tel.: +30 210 6475600). Detailed instructions for the filing of a complaint are provided on the website of the Authority.
COSMOTE Payments will reply free of charge to your requests, without delay, within one month from the receipt of the request. In exceptional cases, such deadline may be extended for two (2) months if this is required due to the complexity of your request. In any case we will inform you on such extension and on the reason of delay.
If we find that your request is manifestly unfounded or excessive, we retain the right to request the payment of a reasonable fee for its satisfaction, considering the administrative costs for its execution, or even to refuse to further process your request.
If you wish to address a question regarding the processing of your personal data to COSMOTE Payments or exercise any of your rights, please consult Data Protection Policy of COSMOTE Payments, which is available here.
11. What kind of measures are applied for the protection of your personal data?
At COSMOTE Payments we provide for the appropriate technical and organizational measures in our corporate procedures, and we apply them in information systems and platforms used for the collection, processing, or use of data.
These are, without limitation:
• Measures for the prevention of access to data processing systems by unauthorized persons (check of login authorization).
• Measures ensuring that unauthorized persons cannot use data processing systems (check of denial of access).
• Measures ensuring that the persons who are authorized to use the data processing systems have access exclusively to data for which they have been authorized, and that personal data cannot be transferred, copied, modified, or deleted by unauthorized persons during their processing, use or following their recording (check of access to data).
• Measures ensuring that during electronic transfer, or during transfer or recording, personal data cannot be transferred, copied, modified, or removed by unauthorized persons and that the processors to whom personal data have been transferred through data transmission equipment may be determined (check of data transfer).
• Measures ensuring that it is possible to examine and determine retroactively if and by whom personal data were entered, altered, or deleted in the data processing systems (check of data entry).
• Measures ensuring that personal data processed by third parties/contractors shall be processed only according to our instructions (check of contractor)
• Measures ensuring that data collected for different purposes can be processed separately (separation rule).