Privacy Policy
Last updated: 28 05 2026
1. What is the purpose of this Privacy Policy?
This Privacy Policy (the “Policy”) describes how we collect, use, disclose, and store your personal data (the “Data”), as well as the statutory rights you have. We protect your Data in accordance with applicable data protection laws, including the EU General Data Protection Regulation 2016/679 (the “GDPR”).
2. Who is my Data Controller?
Name: Nextedge UAB
Registration code: 304230261
Email address: info@railor.eu
Address: Laisves avenue 10A, LT-04215 Vilnius
3. Purposes and legal basis of processing, categories of the Data concerned
3.1. Providing electronic money and payment services
When you apply for, register for, or use our electronic money and payment services, we process your Personal Data to establish and administer your business relationship with us, verify your identity, open and maintain your payment account, execute payment transactions, issue electronic money, provide currency exchange and other payment services, authenticate your access to our services, communicate with you regarding your account and transactions, and ensure the proper delivery and security of our services.
Legal basis for the processing | Categories of the Data concerned | Is the provision of the Data a requirement? |
Contract (Article 6(1)(b) of GDPR) Legal obligation (Article 6(1)(c) of GDPR) | Name and surname, personal identification data (where applicable), date of birth, nationality, e-mail address, telephone number, residential or business address, represented entity (where applicable), company position, payment account details (including IBAN), customer identification number, authentication data, payment instrument information, payment transaction details (including payer and payee information, transaction amount, currency, date, reference and transaction identifiers) | Yes – this is a contractual requirement. If you do not provide the required Personal Data, we may be unable to establish a business relationship with you, open or maintain your payment account, or provide the requested electronic money and payment services |
3.2. Identity verification and prevention of money laundering and terrorist financing (AML/CFT)
We process your Data in order to verify your identity and comply with legal obligations related to the prevention of money laundering, terrorist financing, and related financial crimes.
Legal basis for the processing | Categories of the Data concerned | Is the provision of the Data a requirement? |
Legal obligation (Art. 6(1)(c) of GDPR)
| Name, surname, personal identity number, photograph, gender, country, city, date of birth, identity document data (photo, expiry date, copy of the document), signature, nationality/citizenship, bank account number, payment type, payment purpose/fee title, transaction ID, payer code, payment code, time, amount, place, data required to implement measures for AML/CFT, tax evasion prevention and international sanctions | Yes – this is a statutory requirement. If you do not provide this data, we will not be able to provide our services |
Processing is necessary for reasons of substantial public interest (Art. 9(2)(g) of GDPR) | Information whether you are a politically exposed person (PEP) |
3.3. Handling your inquiries, requests and complaints
When you submit an inquiry, request, or complaint, we process the Data listed below in order to provide you with appropriate support and to ensure proper handling of your case.
Legal basis for the processing | Categories of the Data concerned | Is the provision of the Data a requirement? |
Consent (Article 6(1)(a) of GDPR) Legitimate interest (to handle your inquiries (Article 6(1)(f) of GDPR) | Name, surname, e-mail address, telephone number, residential or business address, the content of the inquiry, request, or complaint, information and documents related to the submitted inquiry, request, or complaint, responses, correspondence records, chat transcripts, and any other information voluntarily provided by you in the course of communication | No |
3.4. Conducting marketing activities & social media profiles
When you register on our website or mobile application, provide us with your consent, or when we have a legitimate interest, we may process your Data for marketing purposes, including sending you relevant offers, updates about our or our partners’ services and goods, and requests for feedback about the services we provide. In addition, when you interact with our social media accounts, we process the Data generated from these interactions in order to administer and improve our social media presence and to communicate with you effectively.
Legal basis for the processing | Categories of the Data concerned | Is the provision of the Data a requirement? |
Consent (Article 6(1)(a) of GDPR) Legitimate interest (to inform you about our services and goods) (Article 6(1)(f) of GDPR) Customer relationship (Article 13(2) of the e-Privacy Directive 2002/58/EC) | Name and surname, e-mail address, telephone number, demographic information (age, gender, location, language preferences), communication preferences and consents, social media identifiers and usernames, profile information (profile photo, description, public interests), comments, reactions, messages sent to us, our replies to your messages, participation in surveys, promotions, contests, reviews, testimonials, and events, browsing behavior on our websites and apps, interactions with marketing communications, device and technical data (IP address, device type, operating system, browser type, advertising identifiers, cookies, pixel tags, and similar technologies), geolocation data (if enabled), social media engagement statistics, ratings | No |
3.5. Security, functionality, and improvement of our services and products
To ensure the security, stability, and proper functioning of our website, mobile application, and products, as well as to protect against fraud, abuse, and unauthorized access, we automatically collect and process certain technical and usage-related data. This information also helps us monitor performance, detect errors, implement product upgrades, develop new features, and improve the overall user experience.
Legal basis for the processing | Categories of the Data concerned | Is the provision of the Data a requirement? |
Legitimate interest (to ensure the security, proper functioning, and continuous improvement of the website, mobile application, and products) (Article 6(1)(f) of GDPR) | IP address, device identifiers, device type and model, operating system and version, browser type and version, screen resolution, language settings, time zone, login data, session identifiers, cookies and similar tracking technologies, browsing and interaction data on the website, in the mobile app, and with product features, referrer URL, geolocation data (if enabled), network and connection information, log files, error and crash data, authentication and access records, user account activity (including login attempts), order history (to detect suspicious or unusual activity), feedback and in-app behavior related to product usage | No |
3.6. Recruitment
When you apply for a vacant position in our company or when we contact you regarding job opportunities, we process your Data related to the recruitment process.
Legal basis for the processing | Categories of the Data concerned | Is the provision of the Data a requirement? |
Consent (Article 6(1)(a) of GDPR) Legitimate interest to contact you regarding job opportunities in our company (Article 6(1)(f) of GDPR) | Name, surname, place of residence or residential address, e-mail address, telephone number, information about work experience (employer, period of employment, position, responsibilities, achievements), information about education (educational institution, period of study, degree and/or qualification obtained), information about training (courses attended, certificates obtained), information about language skills, IT skills and other competences, other information provided in the CV, cover letter or other application documents, name of the referee/recommending person, content of the recommendation, summary of the interview, notes and opinions of the recruiter, results of candidate testing | No |
3.7. Compliance with legal requirements and defence of our legal interests
We will retain the Data in accordance with statutory limitation periods to defend our rights and legal interests if necessary. Some data must be retained to comply with legal requirements in accounting, archiving, and other areas. In rare cases, if you become involved in a legal process to which we are a party, we will use this data for that legal process.
Legal basis for the processing | Categories of Data concerned | Is the provision of the Data a requirement? |
Legal obligation (Article 6(1)(c) of GDPR) Legitimate interest in protecting our rights and legal interests (Article 6(1)(f) of GDPR) | Name, surname, email address, contracts, legally binding documents and data, correspondence, legal documents, pleadings, annexes, court documents, investigative information, information about convictions and criminal offences, logs, possible breaches and incidents, and any other information provided and collected | When the processing of your Data is required under applicable laws, providing this data becomes a legal necessity. If you are unable to provide this data, unfortunately, we will not be in a position to offer our services to you |
4. How long do you keep my Data?
We retain the Data in a form that allows your identity to be determined no longer than necessary for the purposes for which the Data is processed, and in accordance with legal requirements:
- We store copies of documents confirming the identity of the client, e.g. copies of customer’s identity documents, beneficiary identity data, documentation of accounts and/or agreements, and other information related to the customer application and due diligence process for 8 years from the date of the end of business relations with the client.
- We store correspondence of business relations with the client for 5 years from the date of the end of the business relations with the client.
- We store records of monetary transactions, e.g. documents, data, and other legally valid information relating to the execution of monetary transactions or confirming a monetary transaction for 8 years from the date of the execution of the monetary transaction.
- The retention periods specified in points 1 – 3 above may be further extended for up to an additional 2 years where there is a reasoned instruction issued by a competent authority.
- We will use your Data for marketing purposes as long as you or the company you represent is our client or have given us consent, and 3 years thereafter, unless you inform us that you no longer wish to receive such information from us.
- We will retain Data in our social media profiles for no longer than 10 years.
- For managing our recruiting and processing employment applications we will retain the Data that we have obtained via our recruitment processes for as long as necessary to evaluate the application and in accordance with all relevant laws and regulations. Furthermore, we may ask for your consent to retain your Data for some time after we have evaluated your application.
- We will retain other information necessary for the protection of our legal interests for 10 years after the termination of our relationship with you.
5. Where do you collect my Data from?
We collect most of the Data from you. Where necessary for the purposes set out below, we collect Data from other sources.
Source of origin of data | Purpose of processing |
Our clients | To provide our services |
Payment service providers | Processing and confirming payments |
Social media service providers | Managing our social media profiles |
Recruitment agencies, job search portals, professional social networks (e.g. LinkedIn) | Recruitment |
Registers of legal entities | To comply with applicable legislation |
Publicly available sanctions, politically exposed persons (PEP), adverse media and other compliance-related databases, lists and information sources. | To ensure compliance with AML, CTF and fraud prevention requirements |
Public records databases (such as company registries and regulatory filings) and information obtained from publicly available sources through open-source intelligence (OSINT) activities | To ensure compliance with AML, CTF and fraud prevention requirements |
We and/or our third-party verification providers may collect information from private or commercially available sources, including credit reference agencies, fraud prevention agencies and other verification providers, to the extent permitted by applicable law | To ensure compliance with AML, CTF and fraud prevention requirements |
Supervisory authorities, police, prosecutors, courts, law enforcement and other state and municipal authorities, participants in legal proceedings and their representatives | Compliance with legal requirements and defence of our legal interests |
6. Who do you share my Data with?
Where necessary for the above purposes and subject to applicable law, we share data with the following recipients.
Recipients or categories of recipients | If the Data are to be transferred to a third country or an international organisation: | |
Third country | Safeguard measure or exemption allowing the transfer | |
Credit reference, fraud protection, risk management, and identity and verification agencies | — | |
Participants in the transaction processing chain (merchants, acquirers, banks or other card issuers, card associations) | — | |
Lawyers, notaries, bailiffs, data protection officers, auditors, tax, business, HR and other consultants | — | |
Providers of IT tools and services, electronic communications service providers, travel agencies, insurance companies, archiving and other service providers | — | |
State labour, social security, tax, supervisory authorities, police, prosecutors, courts, law enforcement and other state and local authorities | — | |
Elcoin LTD (banking service provider) | UK | |
AMLWatcher.com LLC (customer due diligence (KYC), transaction monitoring and compliance service provider) | USA | |
Facebook (Meta) (social media service provider) | USA | |
LinkedIn (social media service provider) | USA | |
Microsoft Corporation (provider of cloud, productivity and IT infrastructure services) | USA | |
Potential or actual purchasers of the business or part of it and their authorised advisers or representatives | Various | |
7. What rights do I have in relation to the processing of my Data?
My right | Summary |
Right of access | The right to obtain confirmation from us as to whether Data relating to you is being processed and, if such Data is being processed, the right to have access to the Data and information about the processing. |
Right to rectification | The right to require us to rectify inaccurate Data relating to you. |
Right to erasure (‘right to be forgotten’) | – when Data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; – when you withdraw consent on which the processing of Data is based and there is no other legal ground for the processing; – when you object to the processing of Data and there are no overriding legitimate grounds for the processing, or you object to the processing for direct marketing purposes; – where the Data have been unlawfully processed; – where the Data have to be erased for compliance with a legal obligation; – where the Data have been collected in relation to the offer of information society services directly to a child and subject to a consent. |
Right to restriction of processing | – where the accuracy of the Data is contested by you; – where the processing of Data is unlawful and you oppose the erasure of the Data and request the restriction of their use instead; – where we no longer need the Data for the purposes of the processing, but they are required by you for the establishment, exercise or defence of legal claims; where you have objected to the processing of the Data and until it has been verified whether our legitimate interests override yours. |
Right to data portability | where you seek to receive the Data you have provided in a structured, commonly used and machine-readable form or to transmit those data to another controller, the processing is based on consent or on a contract and is carried out by automated means. |
Right to object | where the collection and use of the Data is based on a task carried out in the public interest or in the exercise of official authority vested or legitimate interest, including profiling, as explained in Section 3 of this Privacy Policy, or where you object to the collection of your data for direct marketing purposes. |
Right to withdraw consent | where the processing of Data is based on consent, as explained in Section 3 of this Privacy Policy, and you seek to withdraw it at any time. |
Right to lodge a complaint | Right to lodge a complaint with a supervisory authority |
8. Does your website place cookies on my device?
Yes, our website places the following cookies on your device:
Purpose of processing | Cookie | Category | Whether third parties will have access to the information | Duration of operation |
A first-party session cookie likely used by the website application to maintain temporary state during a browsing session (e.g., routing, session continuity, anti-bot/session integrity, or keeping transient user flow data). Because it is session-scoped (expires at end of session) and the name is not a widely documented standard, the exact function cannot be confirmed from the name alone, but it is typically used to ensure core site functionality during navigation. | Application Session / State Cookie (TURTLE) | Strictly Necessary | No | Session |
A first-party session cookie likely used to store an inferred or selected geographic region (e.g., country/region) to deliver localized content, comply with regional rules, or route the user to the appropriate experience. If used purely for localization (language/region display) it is functional; if used for access control or regulatory gating it may be necessary. With only the cookie name available, the most typical use is localization. | Geolocation / Region Preference Cookie | Functional | No | Session |
Used by the i18next internationalization framework to remember the user’s selected language/locale so the site can display content in the preferred language across pages during the session. | Language Preference Cookie (i18next) | Functional | No | Session |
Set by AWS Elastic Load Balancing to maintain session stickiness to a specific target behind the load balancer. This helps ensure requests from the same user are consistently routed to the same backend instance, improving reliability and preventing session-related errors. | AWS Load Balancer Stickiness Cookie (Target Group) | Strictly Necessary | No | 7 days |
A variant of the AWS load balancer stickiness cookie used in cross-origin contexts. It supports consistent routing (session affinity) when requests are made in scenarios involving CORS, helping core site functionality remain stable. | AWS Load Balancer Stickiness Cookie (Target Group, CORS) | Strictly Necessary | No | 7 days |
Set by AWS Elastic Load Balancing to route a user’s requests consistently to the same backend server during a period of time. This is commonly required for stable operation of login flows, multi-step forms, and other session-dependent features. | AWS Load Balancer Stickiness Cookie | Strictly Necessary | No | 7 days |
CORS-compatible version of the AWS load balancer cookie that supports session affinity in cross-origin request scenarios, helping ensure reliable delivery of the website and its services. | AWS Load Balancer Stickiness Cookie (CORS) | Strictly Necessary | No | 7 days |
9. How can I manage cookies?
You can configure your browser to decline some or all cookies or to ask for your permission before accepting them. Please note that by deleting cookies or disabling future cookies you may be unable to access certain areas or features of our website. You can control the use of functionality cookies, targeting cookies or advertising cookies by adjusting your browser settings. To find out how to manage cookies in your browser, please visit one of the links below:
- Mozilla Firefox: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences
- Google Chrome: https://support.google.com/chrome/answer/95647
- Opera: https://www.opera.com/help/tutorials/security/privacy
- Microsoft Edge: https://privacy.microsoft.com/en-us/windows-10-microsoft-edge-and-privacy
- Safari: https://support.apple.com/guide/safari/manage-cookies-and-website-information-sfri11471/mac
10. Automated decision-making, including profiling
No, we do not make decisions based solely on automated processing of Data, including profiling, which would produce legal effects concerning you or similarly significantly affects you.
11. How can I contact your Data Protection Officer?
You can contact Data Protection Officers at dpo@railor.eu
12. Can this Policy be amended?
We may amend this Policy unilaterally from time to time. Any such amendments will take effect immediately upon publication. Therefore, please visit our website at https://www.railor.eu/ regularly to review the latest version of this Policy.
Last update date: 2026 – 07 – 21
