Paytia Data Processing

Paytia Data Processing

Customer Personal Data Storage, Retention, and Deletion at Paytia

Overview

This article explains:

  • What personal data Paytia stores about end customers

  • Why that data is stored

  • How customer data can be deleted or erased

  • Whether deletion can be self-served or requires support

  • What data (if any) is retained in anonymised or limited form

  • How long customer data is retained

  • Where customer data may exist behind the scenes (logs, backups, linked systems)

Paytia is designed to minimise personal data, never store sensitive card data, and support GDPR and PCI-DSS compliance.


What Personal Data Does Paytia Store About End Customers?

Paytia stores only the personal data required to support secure payments, receipts, scheduling, workflow, and reconciliation.

Important:
Paytia does not store full card numbers (PAN), CVV, or card expiry dates.

Categories of Personal Data Stored

Data CategoryStoredPurpose
Customer first name✅ YesPayment identification and receipts
Customer last name✅ YesPayment identification and receipts
Customer email address✅ YesPayment links, receipts, payment schedules
Telephone number✅ YesCall and transaction cross-reference
Call audio recordings✅ OptionalQuality, compliance, dispute resolution
Call metadata (CDR)✅ YesCall traceability
Transaction metadata✅ YesPayment processing and reconciliation
Reference / invoice numbers✅ YesMerchant reconciliation
Account number (optional field)✅ OptionalMerchant-defined
Webhook payloads✅ YesAPI diagnostics
IP addresses (system-level)⚠ LimitedSecurity and fraud prevention
Cardholder data (PAN, CVV, expiry)❌ NoNever stored
DTMF card entry tones❌ NoSuppressed and discarded


Audio Call Recordings

Paytia can store audio recordings of telephone calls where enabled by the merchant.

Key Points

  • Recording is optional and configurable per account

  • Paytia custom payment flows ensure that payment card entry is never recorded

  • DTMF tones are suppressed before recording

  • Recordings may contain:

    • Customer voice

    • Agent voice

    • Non-sensitive conversation content

Recordings are used for:

  • Quality assurance

  • Training

  • Dispute handling

  • Regulatory or contractual requirements


Where Is Customer Data Visible in the Platform?

Customer-related data is available through the Log Information menu.

Log Information Sub-Menus

1. Transaction Logs

  • Transaction ID and status

  • Reference / invoice number

  • Customer name, address and email data

2. Reports
  • Reference / invoice number

  • Transaction ID and status

  • Customer name, address and email data


2. Call Records

  • Call timestamps

  • Call status

  • CDR ID

  • Telephone number

  • Transaction linkage

  • Phone numbers

3. Third-Party Logs

  • Webhooks sent from Paytia

  • Delivery status

  • Responses received

  • Customer name, address and email data

4. Third-Party Webhook Logs

  • Payloads received from merchant systems

  • Paytia responses


Why Does Paytia Store This Data?

Data is stored strictly for defined operational and regulatory purposes:

  • Processing secure payments

  • Sending payment links and receipts

  • Managing scheduled payments

  • Reconciling payments with merchant systems

  • Linking calls to transactions

  • Supporting audits, disputes, and chargebacks

  • Operational support and troubleshooting

  • Support workflow

Stored Identifiers Explained

IdentifierPurpose
Unique IDLinks Paytia transactions to the acquiring bank or gateway
CDR IDLinks a transaction to a specific telephone call
Reference numberMerchant invoice or order reconciliation
Account numberOptional merchant-defined identifier
Telephone numberProof of call origin and transaction linkage

Where Is Customer Data Stored?

All Paytia customer data is stored in AWS Ireland (EU-West).

Data is stored in clustered databases replicated across datacentre.
All sensitive tagged data is encrypted down to database field table level.
  • No customer data is transferred outside the EU

  • No processing occurs in non-EU regions

  • Regional storage may be introduced in future per account configuration


How Can Customer Data Be Deleted or Erased?

Self-Service via the Platform

Merchants can:

  • Export transaction and log data via Excel export

  • Manage retention settings where available

  • Tag data as sensitive where available

At present, full deletion of customer data is not self-service. When your account is removed all data is automatically deleted as well.


Deletion via Support Request

To delete customer data:

Please include:

  • Merchant account name

  • Customer identifiers (email, reference number, date range)

  • Data types to be deleted (e.g. recordings, transactions)


Does Deletion Fully Remove the Data?

Yes — With Limited, Controlled Exceptions

Data TypeDeletion Outcome
Customer name and emailPermanently deleted
Audio recordingsPermanently deleted
Transaction logsPermanently deleted
Call recordsPermanently deleted
Webhook logsPermanently deleted

Limited Retention (Anonymised)

Some non-identifiable metadata may be retained in a restricted or anonymised form for:

  • Financial audit obligations

  • Fraud detection and prevention

  • Regulatory compliance

This data:

  • Contains no personal identifiers

  • Cannot be linked to an individual

  • Cannot be reverse engineered


Is Any Customer Data Automatically Deleted?

Yes.

Paytia applies configurable data retention policies based on data type and merchant configuration.

Typical Retention Timeframes

Data TypeTypical Retention
Transaction logsConfigurable (commonly 6–24 months)
Call recordsConfigurable
Audio recordingsConfigurable
Webhook logsShort-term diagnostic retention
Security logsLimited retention

Exact retention settings can be confirmed per merchant account.


Is Customer Data Stored Anywhere Else?

Yes, in tightly controlled supporting systems.

Supporting Storage Locations

LocationDescription
Encrypted backupsTime-limited, rotating backups
Security monitoring systemsRestricted access
Integrated systemsOnly where explicitly configured
System images                         System snapshots for immediate operational restoration

Backups and Deletion

  • Backups are encrypted at rest

  • Backups rotate automatically

  • Deleted data is not restored

  • Residual backup data expires as backups age out


Account Deletion

If you request full account deletion:

  • All customer personal data is removed

  • All transaction history is deleted

  • All call records and recordings are erased

  • Secure payment numbers are released and cannot be reused

Merchants should export any required records before requesting deletion.

    • Related Articles

    • Data-capture

      Customizing Data Capture on the Paytia Platform This guide explains how to configure the Data-Capture section on the Paytia platform, including setting up custom fields and enabling the Address Verification System (AVS) to enhance your payment ...
    • Paytia Proxy Gateway

      Technical Overview, Configuration, and Test Guide 1. Overview The Paytia Proxy Gateway is a flexible payment gateway that enables organisations to securely pass captured payment data from their environment to third-party systems using a fully ...
    • Watch demonstration videos of Paytia Agent Capture Assist processing payments securely.

      Demonstration Video: Secure Payment Processing with Agent Capture Assist Watch the following video to see a demonstration of how a business user can assist a customer in making a secure telephone payment using Paytia's Agent Capture Assist. Key ...
    • Does using Paytia combat fraud?

      Does Using Paytia Combat Fraud? The quick answer is yes. Paytia’s solutions are designed to protect your business, staff, and customers from potential fraud risks associated with handling sensitive payment card details. How Paytia Protects Your ...
    • How Paytia’s Telephony Services Enable Secure and Compliant Phone Payments

      As a trusted business providing services to customers, securing customer payment details during telephone transactions is critical. Paytia’s secure payment solutions ensure that businesses can process phone payments without ever seeing or hearing ...