Privacy Policy
How DEVEDGE PAYMENTS LTD. collects, uses, safeguards and discloses personal information.
Last updated: 9 October 2026
1. Who We Are and What This Policy Covers
This Privacy Policy explains how DEVEDGE PAYMENTS LTD. ("DevEdge", the "Company", "we", "us" or "our") handles personal information in connection with the website https://devedgepay.com (the "Website"), its related digital interfaces and the money services we provide to verified corporate clients. DEVEDGE PAYMENTS LTD. is a company incorporated in British Columbia, Canada, under company number BC1579238, with its registered address at 5780 Victoria Dr Unit #170, Vancouver BC V5P 3W7, Canada, and is registered as a Money Services Business with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) under MSB registration number N300001689.
For the purposes of this Policy, "personal information" means any information about an identifiable individual, whether that individual is a client, a director, officer, authorized signatory or beneficial owner of a corporate client, a payment counterparty, or a visitor to the Website. DevEdge acts as the organization accountable for personal information under its control and determines why and how that information is processed. We are committed to keeping that information confidential, accurate and secure throughout the period in which we hold it.
2. Legal and Regulatory Framework
Our handling of personal information is governed primarily by the Personal Information Protection and Electronic Documents Act (PIPEDA) and by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), together with its regulations and the guidance issued by FINTRAC. Because these laws require us to identify our clients, keep records and report certain transactions, some processing described in this Policy is mandatory and cannot be declined if you wish to receive our services.
Where we process personal information of individuals located in the European Economic Area or the United Kingdom, we also take into account the requirements of the General Data Protection Regulation and its UK equivalent, including the rights those laws grant to data subjects.
3. Personal Information We Collect
We limit collection to what is necessary to deliver our services and meet our legal obligations. The identification information we collect typically includes full legal name, date of birth, residential address, nationality, contact details and the type, number and expiry date of government-issued identity documents. For corporate clients we also collect information about the legal entity, its directors, authorized signatories and ultimate beneficial owners.
In the course of providing services we collect transaction information such as amounts, currencies, payment methods, the identity and account details of senders and recipients, the purpose of payment and timestamps. Account information may include business email addresses, telephone numbers, login credentials, nominated bank accounts and the verification documents you upload. Compliance and verification information may include scans of identity documents, facial images captured during biometric checks, proof of address, corporate registry extracts, ownership charts and source of funds or source of wealth evidence.
When you use the Website we automatically collect technical information such as your IP address, browser type, device model, operating system and session identifiers. We also keep records of our communications with you, including support requests, complaints and onboarding correspondence.
4. Why We Use Personal Information and Our Legal Grounds
We use personal information to establish and manage client relationships, verify the identity and eligibility of clients and their related persons, execute payment, remittance and foreign exchange instructions, perform anti-money laundering and counter-terrorist financing checks, detect and prevent fraud, maintain accurate business records and improve the security and functionality of our platform.
We rely on your meaningful and informed consent as required by PIPEDA, and you may withdraw consent at any time subject to legal and contractual restrictions. Much of our processing is also necessary to perform the contract we have with you or your organization, or to comply with legal obligations under anti-money laundering, know-your-customer, sanctions, tax and record-keeping laws. Finally, we process certain information on the basis of our legitimate interests in keeping our systems secure, preventing fraud, managing risk and maintaining service quality, provided those interests are not overridden by your rights.
5. When We Disclose Personal Information
DevEdge does not sell, rent or trade personal information. We disclose it only in defined circumstances and only to the extent necessary. Recipients may include regulated payment processors, correspondent and acquiring banks and card scheme operators involved in executing your transactions, identity verification, sanctions screening and anti-money laundering service providers, fraud prevention organizations and credit reference agencies, and our professional advisers such as auditors and legal counsel.
We will also disclose personal information to FINTRAC, law enforcement agencies, courts and other public authorities where we are required to do so by law, regulation, subpoena or court order. Every third-party service provider we engage is bound by contractual obligations of confidentiality and security and may use the information only to provide services to us.
6. International Transfers
Some of our service providers, banking partners and hosting facilities are located outside Canada, so personal information may be transferred to, stored in or accessed from other jurisdictions in order to process transactions, host our technology or conduct compliance reviews. While abroad, that information may be subject to the laws of the destination country, including lawful access by its authorities. We use contractual, organizational and technical safeguards to ensure that transferred information receives protection comparable to that required under Canadian privacy law.
7. How We Protect Personal Information
We protect personal information with safeguards appropriate to its sensitivity. These include encryption of data in transit and at rest, multi-factor authentication, role-based access controls limited to staff who need the information for their duties, logging and monitoring of system access, regular vulnerability testing and secure data destruction procedures. Where payment card data is handled, it is processed by partners certified under the Payment Card Industry Data Security Standard (PCI DSS), and DevEdge does not store full card numbers on its own systems. In the event of a breach of security safeguards that creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as required by PIPEDA.
8. How Long We Keep Information
In line with FINTRAC record-keeping requirements, we retain identification and transaction records for at least five years from the date of the last transaction or the end of the business relationship, whichever is later. Other information is kept only as long as needed for the purpose for which it was collected or as required by law. At the end of the applicable retention period, information is securely deleted, destroyed or anonymized.
9. Your Privacy Rights
Under PIPEDA you have the right to request access to the personal information we hold about you, to ask that inaccurate or incomplete information be corrected and to challenge our compliance with privacy requirements. We will respond to a written access request within 30 days, and may need to verify your identity before doing so. In limited cases the law requires or permits us to refuse access, for example where disclosure would reveal that a report has been made to FINTRAC; if so, we will explain the reasons where we are allowed to.
Individuals in the European Economic Area or the United Kingdom may additionally have the rights of erasure, restriction, portability and objection described in Articles 15 to 22 of the GDPR, subject to our overriding legal retention duties. If you are not satisfied with our response, you may lodge a complaint with the Office of the Privacy Commissioner of Canada or, where applicable, your local data protection authority.
10. Cookies
The Website uses cookies and similar technologies to enable secure access, remember your preferences, understand how the Website is used and, with your consent, deliver relevant content. Strictly necessary cookies are always active, while analytical and marketing cookies are only set after you give consent through our cookie banner. Full details are set out in our Cookie Policy.
11. Minors
Our services are intended exclusively for businesses and are not directed at individuals under the age of majority in their province or country of residence. We do not knowingly collect personal information from minors, and any such information received in error will be deleted.
12. Updates to This Policy and How to Contact Us
We may amend this Privacy Policy to reflect changes in law, regulatory expectations or our internal procedures. The current version will always be available on the Website with its "last updated" date, and we will give advance notice of material changes through the Website or by email.
Questions, access requests and complaints should be addressed to our Privacy Officer at DEVEDGE PAYMENTS LTD., 5780 Victoria Dr Unit #170, Vancouver BC V5P 3W7, Canada, or by email at compliance@devedgepay.com. Company number BC1579238, jurisdiction British Columbia, Canada, website https://devedgepay.com.