Effective Date: June 10, 2025 | Last Updated: June 10, 2025
GoCross Ltd. (“GoCross”, “we”, “us”, or “our”) is a company incorporated in Malta that provides payment gateway services to merchant clients globally (“Merchants”). This Privacy Policy describes how we process personal data shared with us by our Merchant clients in the course of providing payment processing and related services.
GoCross operates as a business-to-business (B2B) service provider and does not collect personal data directly from individual users (“Data Subjects”). All personal data processed by GoCross is obtained from and on behalf of our Merchant clients, who act as data controllers.
We may process the following types of personal data, as provided by our Merchant clients:
Our processing activities are governed by the General Data Protection Regulation (EU Regulation 2016/679 - “GDPR”) and are undertaken on the following legal bases:
We process personal data solely for the following purposes:
In the performance of our services, personal data may be transferred to third parties or subprocessors, including service providers located outside the European Economic Area (EEA). Such transfers are conducted in strict accordance with Chapter V of the GDPR. Where data is transferred to a country not deemed to provide an adequate level of data protection by the European Commission, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms.
We retain personal data only for as long as is necessary to fulfill the purposes outlined in this Privacy Policy, or as required to comply with applicable legal, regulatory, tax, or accounting obligations. When personal data is no longer required for these purposes, it is securely deleted or anonymized in accordance with our data retention policies.
GoCross employs robust, industry-standard technical and organizational security measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include, but are not limited to:
As GoCross acts as a data processor on behalf of our Merchant clients, we do not directly respond to data subject requests. Individuals wishing to exercise their rights regarding their personal data (such as access, rectification, erasure, restriction of processing, objection to processing, or data portability) should direct their requests to the relevant Merchant (the data controller). We are committed to cooperating fully with our Merchant clients to help them fulfill such requests in accordance with applicable data protection laws.
For any questions or concerns related to this Privacy Policy or our data processing practices, please contact: