1. Who we are and how to contact us
Anton Payments Inc. is a Canadian federal corporation (Corporation No. 1781501-8) with its registered and head office at 4145 N Service Road, 2nd Floor, Burlington, Ontario L7L 6A3, Canada. Anton Payments Inc. operates cross-border payout infrastructure and the Anton Intelligence compliance and risk decisioning platform (together with our website, APIs, dashboards, and documentation, the "Services").
Anton Intelligence USA LLC is a Wyoming limited liability company and an affiliate of Anton Payments Inc., registered with FinCEN as a money services business. Where we identify a different controlling entity for a given service in your customer agreement or order form, that agreement governs.
In this Policy, "Anton", "we", "us", and "our" mean the Anton entity that determines the purposes and means of processing your personal information for the relevant Service, as described in Section 3.
1.1 Privacy Officer
We have designated an individual accountable for our compliance with this Policy and with applicable privacy law, as required by the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Act respecting the protection of personal information in the private sector (as amended by Law 25).
Privacy Officer
Anton Payments Inc.
4145 N Service Road, 2nd Floor
Burlington, Ontario L7L 6A3, Canada
+1 (289) 246-7624
1.2 European Economic Area and United Kingdom
We do not currently offer or market the Services to individuals in the EEA or the UK. We may nonetheless process personal information about individuals located there where a customer instructs us to execute a payout to a payee in those regions. In that case we act as a processor on that customer's instructions, and the customer is responsible for its own obligations as controller.
We will appoint a representative under Article 27 of the GDPR and of the UK GDPR, and publish that appointment here, before we begin offering the Services to individuals in those regions. Until then, the EEA and UK annex in Section 14.2 applies to any processing to which the GDPR or UK GDPR does apply.
1.3 Data protection officer
We have assessed our processing and have not appointed a Data Protection Officer under Article 37 of the GDPR. Privacy questions should be directed to our Privacy Officer, whose contact details appear above.
2. Scope
This Policy applies to personal information we handle in connection with the Services, our website at antonpayments.com and its subdomains, our developer documentation, our trust centre, our investor materials, our marketing and events, and our recruiting.
It does not apply to:
- The privacy practices of our customers. Where a platform, marketplace, or merchant uses Anton to pay its users, that customer is responsible for its own privacy notices and for the lawfulness of the data it sends us.
- Third-party sites, payment networks, or financial institutions that we link to or interoperate with. Those parties act under their own privacy policies.
- Anonymized or aggregated information that cannot reasonably be used, alone or in combination, to identify an individual.
3. Our role: when we are a controller and when we are a processor
This distinction determines who you should contact to exercise your rights, and it is the most important section of this Policy for payees.
3.1 We act as a processor (a "service provider" under US state law) when:
We receive payee and transaction data from a customer in order to execute payouts and return decisioning results to that customer. In that role we process personal information only on the customer's documented instructions, under a written data processing agreement. The customer is the controller. Our data processing agreement is available from legal@antonpayments.com.
If you are a payee and you want to access, correct, or delete your information, contact the platform that pays you first. We will assist that platform in responding to you. If you cannot identify or reach the platform, contact us at privacy@antonpayments.com and we will make reasonable efforts to route your request.
3.2 We act as a controller when:
- We are subject to our own legal obligations that we cannot delegate, including customer due diligence, sanctions screening, transaction monitoring, record keeping, and suspicious transaction and activity reporting under Canada's Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and the US Bank Secrecy Act. In this role we determine what we collect and how long we keep it, and a customer cannot instruct us to delete it.
- We operate the Payee Intelligence Graph and our risk models for fraud prevention and financial crime detection across our platform, as described in Sections 7 and 8.
- We manage our own commercial relationships: customer accounts and administrators, prospects, partners, investors, job applicants, website visitors, and support correspondents.
We are therefore a joint or independent controller alongside our customers for compliance-mandated processing, and a processor for the rest. Where our roles overlap for the same data, the higher standard applies.
4. Whose personal information we handle
| Category | Who they are | How we usually get their data |
|---|---|---|
| Customer personnel | Employees, founders, and administrators at platforms and financial institutions that use Anton | Directly from them |
| Payees | Individuals and sole proprietors who receive funds through our rails | From our customers, and directly during verification |
| Beneficial owners and control persons | Individuals behind business customers and business payees | From the business, and from public and commercial registries |
| Partners and vendor contacts | Referral, banking, and technology partners | Directly, and from our partners |
| Investors and prospects | Individuals in our fundraising and sales pipelines | Directly, from public sources, and from introductions |
| Website visitors | Anyone visiting our sites | Automatically, as described in Section 15 |
| Applicants | Candidates for roles at Anton | Directly, and from recruiting platforms |
Notice to payees. In most cases we receive your information from the platform paying you rather than from you. This Policy serves as our notice under Article 14 of the GDPR and equivalent provisions elsewhere. The categories, purposes, recipients, retention periods, and rights described below apply to you.
5. Personal information we collect
5.1 Identity and verification data
Full name, date of birth, nationality and country of residence, residential or business address, government-issued identification documents and their numbers (passport, driver's licence, national ID), government identifiers where legally required for tax or verification purposes (including SIN, SSN, ITIN, EIN, or foreign equivalents), photographs and selfies submitted for identity verification, liveness and document-authenticity signals produced by our verification provider, business registration and incorporation documents, ownership and control structure, and beneficial ownership declarations.
Biometric information. Our identity verification flow, operated by Persona, performs a facial comparison between a selfie or short video you submit and the photograph on your identity document, together with liveness detection to confirm that a live person is present. This produces biometric identifiers and biometric information.
- Purpose. We use it for one purpose only: confirming that you are the person shown on the identity document you have presented, and detecting impersonation and synthetic identity fraud. We do not use it to identify you in any other context, to build a facial recognition database, or for any advertising, profiling, or marketing purpose.
- Consent. We collect and use biometric information only with your express consent, obtained at the point of verification before any capture occurs. If you do not consent, contact the platform paying you or write to privacy@antonpayments.com about alternative verification. Withdrawing consent does not undo verification already completed, and we may be unable to onboard or continue to serve you without a verified identity.
- Disclosure. We do not sell, lease, trade, or otherwise profit from biometric information, and we do not disclose it except to Persona as our verification provider, and where compelled by a warrant, subpoena, or other lawful order.
- Retention and destruction. The facial geometry template generated for the comparison is discarded once the comparison is complete. Neither we nor Persona retain it, and no template is stored, indexed, or reused. In no event is biometric information retained beyond three years after your last interaction with us. The identity document image and the verification outcome are retained separately, as records of the verification, under the record keeping obligations in Section 12.
- Safeguards. Biometric information is stored and transmitted using at least the standard of care we apply to other confidential information, and no less than the standard we apply to other sensitive personal information.
See Section 14.5 for state-specific biometric notices.
5.2 Financial and transaction data
Bank account and payment instrument details, routing and clearing identifiers, wallet addresses where applicable, payout amounts, currencies, corridors, timestamps, counterparties, payment purpose and reference fields, transaction status and failure reasons, fees, foreign exchange rates applied, balances, funding and settlement records, and chargeback, return, and dispute records.
Payment instrument data is stored in a PCI DSS Level 1 certified tokenization vault operated by Basis Theory and is not held in our core systems in raw form.
5.3 Risk and compliance data
Sanctions, politically exposed person, and adverse media screening results and their disposition, watchlist and negative-file matches, our transaction risk score (TRS) and originator risk score (ORS), the individual rule outcomes and severity contributions that produced those scores, case notes, alert dispositions, escalation and human review records, device and behavioural signals used for fraud detection, and records of reports filed with regulators.
Where we have filed a suspicious transaction report or suspicious activity report, we are prohibited by law from telling you, and we cannot confirm or deny that any such report exists. This limits what we can disclose in response to an access request.
5.4 Account and usage data
Account credentials and authentication factors, API keys and their usage, roles and permissions, configuration and policy settings you define, audit logs of actions taken in our dashboards, and support tickets, emails, and chat transcripts.
5.5 Technical data
IP address, approximate location derived from IP address, browser and device type, operating system, device identifiers, referring URLs, pages and features accessed, timestamps, request and response metadata, error and performance telemetry, and cookie identifiers. We do not collect precise geolocation.
5.6 Data from third parties
Identity verification and KYC/KYB providers, sanctions and watchlist data providers, credit bureaus and business information providers, banking and payment partners confirming account validity and settlement status, corporate and beneficial ownership registries, public sources including regulatory enforcement lists and adverse media, and referral partners.
5.7 Sensitive personal information
We collect government identification numbers, financial account details, identity documents, and biometric information used to verify identity. Under the California Consumer Privacy Act these are "sensitive personal information", and biometric information is separately regulated in several jurisdictions as described in Sections 5.1 and 14.5. We collect and use them only for the purposes set out in Section 6, principally identity verification, fraud prevention, and legal compliance. We do not use or disclose sensitive personal information for inferring characteristics about you, and we do not use it for advertising.
6. Why we use personal information, and our legal basis
| Purpose | What it involves | Legal basis (GDPR / UK GDPR) | Basis under PIPEDA and Canadian law |
|---|---|---|---|
| Providing the Services | Account creation, payout execution, settlement, balances, API access, support | Performance of a contract; legitimate interests where you are not the contracting party | Consent, or implied consent and business transaction exception |
| Identity verification and due diligence | KYC, KYB, beneficial ownership, ongoing monitoring | Legal obligation; performance of a contract | Legal requirement; s. 7 collection without consent for investigation of breaches of law |
| Biometric facial comparison | Matching a selfie to an identity document, liveness detection | Explicit consent under Art. 9(2)(a), supporting a legal obligation | Express consent, required for biometric verification |
| Sanctions and watchlist screening | Screening parties against sanctions, PEP, and adverse media lists | Legal obligation; substantial public interest under Art. 9(2)(g) for any special category data | Legal requirement under PCMLTFA and sanctions legislation |
| Transaction monitoring and risk scoring | Rule evaluation, severity scoring, alerting, case management | Legal obligation; legitimate interests in preventing fraud and financial crime | Legal requirement; s. 7(3)(d.2) and fraud prevention provisions |
| Regulatory reporting | Reports to FINTRAC, FinCEN, and other authorities | Legal obligation | Legal requirement |
| Fraud and abuse prevention across the network | Entity resolution and cross-customer risk signals, described in Section 7 | Legitimate interests (Recital 47); legal obligation | s. 7(3)(d.2), disclosure and use for fraud detection and prevention |
| Security and availability | Logging, monitoring, incident response, access control | Legitimate interests; legal obligation | Reasonable purposes; safeguarding requirement |
| Service improvement and model development | Analytics, evaluation, model tuning, subject to Section 8 | Legitimate interests | Consent or de-identification, as described in Section 8 |
| Marketing and events | Newsletters, product announcements, invitations | Consent, or legitimate interests for business-to-business contacts | Express or implied consent under PIPEDA and CASL |
| Corporate and investor relations | Fundraising, diligence, cap table administration | Legitimate interests; legal obligation | Business contact information exemption; consent |
| Legal claims and enforcement | Disputes, collections, defence of claims | Legitimate interests; establishment or defence of legal claims | s. 7(3) exceptions for legal proceedings |
| Recruiting | Assessing applicants | Steps prior to a contract; legitimate interests | Consent |
Where we rely on legitimate interests, we have carried out and documented a balancing assessment. You may request a summary of the relevant assessment at privacy@antonpayments.com.
Consent is not the basis for our compliance processing. You cannot withdraw consent to sanctions screening, identity verification, transaction monitoring, or record retention, because we perform these to satisfy legal obligations. If you do not wish to be subject to them, you cannot use the Services.
7. Cross-customer entity resolution and the Payee Intelligence Graph
We operate a Payee Intelligence Graph that resolves payee identities across the customers we serve, using financial identifiers such as bank account and instrument identifiers, together with name, address, and jurisdiction signals.
What this means in practice. If you receive funds through more than one platform that uses Anton, we may link those records to the same underlying entity. We use those links to detect patterns that are not visible to any single platform, including sanctions evasion, identity reuse, mule networks, structuring, and duplicate or fraudulent onboarding. The result may be a risk signal that influences a decision on a payout at a platform other than the one where the underlying behaviour occurred.
What we do not do. We do not disclose to one customer the identity of another customer you transact with, the amounts you receive elsewhere, or your transaction history at another platform. Customers receive risk signals, scores, and reason codes, not the underlying records of other customers.
Legal basis. We rely on our legitimate interests in preventing fraud and financial crime, and on our legal obligations to conduct effective transaction monitoring and screening. In Canada we rely on the provisions of PIPEDA that permit collection, use, and disclosure without consent for the detection and prevention of fraud and for investigating breaches of agreements or law.
Your rights here. You may object to processing based on legitimate interests as described in Section 13. Where the same processing is also required to meet our legal obligations, we will continue it, and we will tell you which parts of the processing your objection can and cannot stop.
8. Automated decision-making and Anton Intelligence
Read this section if you are a payee. It describes decisions made about you by software.
8.1 What is automated
Anton Intelligence evaluates transactions and parties in real time. It combines:
- Sentinel, which applies current regulatory and sanctions requirements
- Engine, which applies deterministic rules, currently more than 24, each producing a weighted severity contribution
- Brain, which applies a fine-tuned language model to judgment-dependent questions such as the plausibility of a stated payment purpose or the significance of an adverse media match
These produce a transaction risk score and an originator risk score on a 0 to 1000 scale, along with reason codes, and a recommended disposition.
8.2 What decisions can result
Depending on the score, the applicable rules, and the configuration set by the platform you are paid by, a transaction may be approved, held for manual review, delayed pending additional information or documentation, declined, or reported to a regulator. Repeated or severe outcomes may result in an account being restricted or closed.
Some of these decisions are made without human involvement and may have a legal or similarly significant effect on you, in particular the withholding or rejection of a payment.
8.3 The logic involved, in plain terms
A score reflects the accumulated severity of matched conditions. Conditions include: matches against sanctions, PEP, or watchlist data; mismatches between the identity documents provided and other records; corridor and counterparty risk associated with the countries involved; the amount and pattern of the transaction relative to prior behaviour; velocity and structuring indicators; links surfaced by the entity resolution described in Section 7; and the outcome of the model's assessment of narrative and contextual fields. Higher accumulated severity produces a higher score and a more restrictive recommended disposition. Thresholds differ by customer and corridor.
Sanctions matches are not scored. A confirmed match against an applicable sanctions list results in a block, as a matter of law, regardless of any other factor.
8.4 Safeguards and your right to a human
Except where the decision is a sanctions block required by law, you have the right to:
- Obtain human intervention in the decision
- Express your point of view and provide additional information or documents
- Contest the decision and receive an explanation of the principal factors behind it
- Request correction of any inaccurate personal information used in the decision
To exercise these rights, contact the platform paying you, or write to us at privacy@antonpayments.com with the transaction reference. A qualified compliance analyst, not an automated system, will review the case. We aim to respond within 10 business days and will confirm the outcome in writing.
We monitor our models for accuracy and for disparate outcomes, we retain a decision record and the inputs behind each material decision for audit, and we do not use special category or sensitive personal information as a scoring feature except where required for sanctions and PEP screening.
8.5 Limits on what we can tell you
We will explain the principal factors in a decision. We will not disclose model weights, exact thresholds, rule logic in a form that would allow it to be evaded, or the fact or content of any report filed with a financial intelligence unit. Anti-tipping-off law prohibits the last of these.
This section also constitutes our notice under section 12.1 of Quebec's private sector privacy legislation, which requires that individuals be informed when a decision is based exclusively on automated processing.
9. Use of data for model development
We train, tune, and evaluate the models used by Anton Intelligence. Our commitments:
- We do not use identifiable customer or payee personal information to train or fine-tune our models.
- We use de-identified and aggregated compliance outcomes, including rule hit patterns, typologies, and analyst dispositions, to improve detection quality. De-identification is performed before data enters any training or evaluation set, and we do not attempt to re-identify it.
- Anton Brain is operated on infrastructure we control. Personal information processed for decisioning is not sent to a third-party model provider for that provider's own training purposes.
- Where a customer agreement or applicable law requires opt-in for any use of that customer's data in model development, we obtain it. Customers may contact legal@antonpayments.com regarding their agreement's terms.
10. When we disclose personal information
We do not sell personal information, and we do not share it for cross-context behavioural advertising or targeted advertising, as those terms are defined under California and other US state privacy laws. We have not done so in the preceding twelve months. We do not operate advertising or cross-site tracking technology on our website.
No data is ever used for advertising. Identity, transaction, risk, and payee information is never disclosed to advertising vendors, used to build advertising audiences, or used for any purpose other than those in Section 6.
We disclose personal information to:
10.1 Our customers
Payout results, verification outcomes, risk scores, reason codes, and case status are returned to the platform that submitted the transaction, subject to the limits in Section 7.
10.2 Sub-processors and service providers
We use vendors to operate the Services. Each is bound by written terms that limit their use of personal information to our instructions, require appropriate security, and impose equivalent obligations on their own sub-processors.
| Sub-processor | Purpose | Primary processing location |
|---|---|---|
| Google Cloud Platform | Core infrastructure and data hosting | Canada (northamerica-northeast2, Toronto) |
| Basis Theory | Tokenization vault for payment instruments and identity data | United States |
| Persona | Identity verification and document authentication | United States |
| WorkOS | Single sign-on and directory synchronization | United States |
| Plain | Customer support ticketing and correspondence | United States |
| Rootly | Incident management | United States |
| Resend | Transactional and marketing email delivery | United States |
| HubSpot | Customer and investor relationship management | United States |
| Google Analytics and PostHog | Website and product analytics | United States |
In addition to the named sub-processors above, we rely on two categories of recipient that we do not name publicly because our agreements with them are subject to confidentiality obligations:
- Sanctions, watchlist, and adverse media data providers, which supply the screening data used for the checks described in Sections 5.3 and 8, located in the United States and the European Union.
- Banking, payment, and settlement partners, which execute and settle transactions, located in the jurisdictions relevant to each corridor we support.
Customers and prospective customers may obtain the identities of these parties, together with their processing locations and the safeguards applying to them, on request under a confidentiality agreement. Write to legal@antonpayments.com. We will not withhold this information from a customer that needs it to meet its own obligations as a controller.
A current list of sub-processors is maintained at trust.antonpayments.com. Customers may subscribe to notifications of changes at that address. We will give at least 30 days' notice before adding a sub-processor that processes customer personal information, during which a customer may object on reasonable data protection grounds.
10.3 Financial institutions and payment networks
Banks, payment processors, clearing systems, and correspondent institutions receive the information necessary to execute a payment. They act as independent controllers under their own obligations.
10.4 Regulators, law enforcement, and courts
We disclose personal information where required or permitted by law, including reports to FINTRAC, FinCEN, and other financial intelligence units, responses to lawful production orders, subpoenas, warrants, and requests from supervisory and law enforcement authorities, and disclosures to auditors and examiners. We assess each request for validity and scope, and we disclose only what is required. Where we are legally able to notify you, we will.
10.5 Professional advisors
Lawyers, auditors, accountants, and insurers, under duties of confidentiality.
10.6 Corporate transactions
In connection with a financing, merger, acquisition, reorganization, or sale of assets, including diligence conducted under confidentiality agreement. If a transaction completes, this Policy will continue to govern the transferred information until the recipient provides notice of a change, and where required we will notify you.
11. International transfers
Our primary infrastructure is hosted in Canada. Personal information is nonetheless transferred to and processed in other countries, including the United States, in connection with our sub-processors, our US affiliate, and the payment partners required to move funds across borders. Cross-border payouts inherently require transferring payee information to the destination jurisdiction.
Safeguards we rely on:
- Canada. The European Commission's 2001 adequacy decision covering organizations subject to PIPEDA in their commercial activities remains in force. It was reviewed and confirmed on 15 January 2024, and the next scheduled review is expected in or around 2028. Anton Payments Inc. is subject to PIPEDA, so transfers from the EEA to us do not require additional safeguards. The decision does not extend to processing that falls outside PIPEDA.
- Standard Contractual Clauses. We use the European Commission's SCCs, and the UK International Data Transfer Addendum, for transfers not covered by an adequacy decision, together with a documented transfer impact assessment.
- Quebec. We do not currently provide the Services in Quebec. Where Quebec law applies to a transfer, we conduct and document a privacy impact assessment before communicating personal information outside the province, as Law 25 requires.
- Contractual and technical measures. Encryption in transit and at rest, tokenization of payment instruments, access minimization, and contractual commitments regarding government access requests.
You may request a copy of the relevant transfer mechanism, with commercially confidential terms redacted, at privacy@antonpayments.com.
12. How long we keep personal information
| Record type | Retention period | Driver |
|---|---|---|
| Biometric templates | Discarded on completion of the comparison, not retained | Illinois BIPA, Texas CUBI, and equivalent state law |
| Client identification and due diligence records | 5 years after the account is closed or the last business relationship ends | PCMLTFA; Bank Secrecy Act |
| Transaction records, receipts of funds, and payout records | 5 years from the date of the transaction | PCMLTFA; Bank Secrecy Act |
| Suspicious transaction and activity reports and supporting records | 5 years from the date of filing | PCMLTFA; Bank Secrecy Act |
| Sanctions screening results and dispositions | 5 years from the screening event | Sanctions legislation; PCMLTFA |
| Risk decision records, scores, and reason codes | 5 years from the decision | Audit and defensibility of automated decisions |
| Customer account and configuration records | Term of the agreement plus 7 years | Contract, limitation periods, tax |
| Support correspondence | 3 years from closure | Business need |
| Website and access logs | 12 months | Security |
| Marketing contacts | Until consent is withdrawn, plus 3 years of proof of consent | CASL requires records of consent |
| Recruiting records | 12 months from the decision, or longer with consent | Business need; human rights complaint periods |
| Breach and confidentiality incident records | 24 months minimum | PIPEDA breach record requirement |
Longer retention applies where a legal hold, investigation, dispute, or regulatory examination requires it. At the end of a retention period we delete or irreversibly de-identify the information.
Deletion requests do not override these periods. Where you ask us to delete information we are required to keep, we will restrict its use to the legal purpose it is retained for and delete everything not subject to the requirement.
13. Your rights
Subject to verification and to the limits described below, you may:
- Access the personal information we hold about you, and be told how it is used and to whom it has been disclosed
- Receive a portable copy in a structured, commonly used, machine-readable format, and have it transmitted to another organization where technically feasible
- Correct inaccurate or incomplete information
- Delete information, where we are not required to keep it
- Restrict or object to processing based on legitimate interests, including profiling
- Withdraw consent where processing is based on consent, without affecting processing already carried out
- Obtain human review of an automated decision, as described in Section 8.4
- Opt out of marketing at any time, using the unsubscribe link or by writing to us
- Complain to a supervisory authority, as described in Section 20
13.1 How to exercise your rights
Write to privacy@antonpayments.com, or to the Privacy Officer at the address in Section 1.1. Include enough detail to identify the records you are asking about. If you are a payee, include the platform that paid you and a transaction reference where possible.
We will acknowledge your request promptly and respond within 30 days, or within the shorter period required by applicable law. We may extend by a further 30 days for complex requests, and we will tell you if we do. We do not charge a fee unless a request is manifestly unfounded or excessive, in which case we will tell you the fee before proceeding.
An authorized agent may submit a request on your behalf with written proof of authority. We may still require you to verify your identity directly.
13.2 Verification
Because our records include financial and identity data, we verify requests before acting. We match the information you provide against our records and may ask for additional confirmation. We will not use information collected for verification for any other purpose.
13.3 Limits on your rights
We may refuse or partially refuse a request where:
- Disclosure would reveal the existence or content of a suspicious transaction or activity report, or would otherwise tip off a subject of an investigation. This is a legal prohibition, not a discretionary choice.
- The information is subject to solicitor-client or litigation privilege.
- Disclosure would reveal personal information about another individual, or confidential commercial information, and it cannot be severed.
- The information was generated in the course of a formal dispute resolution process.
- The information was collected without consent for the purpose of investigating a breach of an agreement or of law.
- We are required by law to retain the information.
Where we refuse, we will tell you why, which provision we rely on, and how to challenge the decision, unless telling you is itself prohibited.
14. Regional annexes
14.1 Canada
We are subject to PIPEDA. Residents of Alberta and British Columbia have parallel rights under provincial legislation. We do not currently provide the Services in Quebec. Where Quebec law applies, residents there have additional rights, including data portability and the right, on request, to be informed of the personal information used in an automated decision, the reasons for it, and the principal factors that led to it. We grant those rights to all individuals as a matter of practice, as set out in Sections 8 and 13.
Complaints may be made to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to the Commission d'accès à l'information du Québec, the Office of the Information and Privacy Commissioner of Alberta, or the Office of the Information and Privacy Commissioner for British Columbia, as applicable.
14.2 European Economic Area and United Kingdom
We do not currently offer the Services to individuals in the EEA or the UK. This annex applies where the GDPR or UK GDPR nonetheless applies to our processing, including where we act as a processor for a customer that is itself subject to those laws, and it will apply in full when we launch in those regions.
The controller is identified in Section 1. Legal bases are set out in Section 6. You have the rights in Chapter III of the GDPR, including access, rectification, erasure, restriction, portability, objection, and the rights in Article 22 regarding automated decisions, addressed in Section 8. You may lodge a complaint with your local supervisory authority, or with the Information Commissioner's Office in the UK.
Automated decision-making described in Section 8 is carried out on the basis that it is necessary for entering into or performing a contract, and that it is authorized by law for the prevention of money laundering and terrorist financing, with the safeguards described in Section 8.4.
14.3 California
Notice at collection. The categories of personal information we collect, the purposes, and the retention periods are set out in Sections 5, 6, and 12. Mapped to the statutory categories, we collect: identifiers; personal information listed in the customer records statute; characteristics of protected classifications where nationality or age is required for compliance; commercial information; internet or network activity; approximate geolocation; audio and electronic information in support recordings and correspondence; professional or employment information; inferences in the form of risk scores; and sensitive personal information as described in Section 5.7.
We disclose these categories for business purposes to the recipients in Section 10. We do not sell personal information and we do not share it for cross-context behavioural advertising.
Your rights. To know, access, correct, delete, limit the use of sensitive personal information, opt out of sale or sharing, and not be discriminated against for exercising these rights. Because we do not sell or share, there is no opt-out to exercise. Our use of sensitive personal information is limited to purposes for which the right to limit does not apply, namely verifying identity, preventing fraud, ensuring security, and complying with law. Submit requests as described in Section 13.1. If we deny a request, you may appeal by replying to our response with the word "appeal", and you may complain to the California Privacy Protection Agency or the Attorney General.
14.4 Other US states
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights to access, correct, delete, obtain a portable copy, opt out of targeted advertising, sale, and certain profiling, and to appeal a denial. We honour the Global Privacy Control and other recognized universal opt-out signals where applicable law requires it. Use the process in Section 13.1. Appeals may be submitted to privacy@antonpayments.com with the subject line "Privacy appeal", and we will respond within 45 days with a written explanation.
14.5 Biometric information notice
This notice supplements Section 5.1 and applies to residents of jurisdictions with specific biometric statutes, including Illinois, Texas, Washington, and Colorado. It is provided in writing before any collection occurs.
What we collect: A facial image or short video captured by you during verification, and a facial geometry comparison between that image and the photograph on your identity document, along with liveness signals.
Why: Solely to confirm that you are the person identified in the document you presented, and to detect impersonation and identity fraud. This supports obligations we have under anti-money laundering law.
Who receives it: Persona, our identity verification provider, acting on our instructions under written terms. No one else, except where compelled by a warrant or other lawful order. We do not sell, lease, trade, or otherwise profit from it.
How long we keep it: The facial geometry template is discarded as soon as the comparison is complete. It is not stored by us or by our verification provider. In no event is biometric information retained beyond three years after your last interaction with us. Our written retention and destruction schedule is available at privacy@antonpayments.com.
Your consent: We obtain your written release before collection. You may decline. If you decline, we will offer an alternative verification method where one is available to us, and where none is available we will be unable to complete verification.
Quebec. We do not currently verify the identity of, or provide the Services to, residents of Quebec. Quebec law requires express consent for biometric identity verification and requires that the creation of a database of biometric characteristics be disclosed to the Commission d'accès à l'information in advance. We will make that disclosure before verifying any Quebec resident.
15. Cookies, analytics, and tracking
We use strictly necessary cookies for authentication, session management, load balancing, consent storage, and fraud prevention. These are set without consent because the Services cannot function without them.
We also use the following non-essential technologies:
| Technology | Provider | Purpose | Category |
|---|---|---|---|
Google Analytics (_ga, _gid) | Website usage measurement | Analytics | |
PostHog (ph_phc_*) | PostHog | Product usage analytics | Analytics |
We do not run advertising tags, retargeting pixels, or cross-site tracking technology on our website.
We do not set these until you consent through our cookie banner, where consent is required by applicable law. You can change or withdraw your choices at any time through our cookie preference centre at antonpayments.com/legal/cookies. Withdrawing consent does not affect processing already carried out.
Global Privacy Control. We honour the Global Privacy Control and other recognized universal opt-out signals as an opt-out of sale, sharing, and targeted advertising where applicable law requires it. We do not respond to Do Not Track signals, because no common standard exists for interpreting them.
16. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including:
- Encryption in transit using TLS, and at rest using AES-256
- Tokenization of payment instruments and identity data in a PCI DSS Level 1 certified vault, isolated from our core database
- Role-based access control, least privilege, mandatory multi-factor authentication, and periodic access review
- Network segmentation, firewalling, intrusion detection, and denial of service protection
- Signed and verified build and deployment pipelines
- Centralized logging, continuous monitoring, and a formal incident response process
- Vulnerability management, dependency scanning, and periodic penetration testing
- Background checks, confidentiality obligations, and recurring security and privacy training for personnel
- Vendor security assessment before onboarding and periodically thereafter
Our certification status, including SOC 2, ISO 27001, ISO 42001, and PCI DSS, is published and kept current at trust.antonpayments.com. Where a programme is in progress rather than complete, that page says so, and this Policy does not claim otherwise.
No system is perfectly secure. We cannot guarantee absolute security, and we ask you to protect your credentials and to notify us immediately at security@antonpayments.com if you suspect unauthorized access.
17. Breach and incident notification
If a breach of security safeguards creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, and we will keep a record of every breach for at least 24 months, as PIPEDA requires. Where the GDPR applies, we will notify the competent supervisory authority within 72 hours of becoming aware, and affected individuals without undue delay where the risk to their rights and freedoms is high. Where Quebec law applies, we will notify the Commission d'accès à l'information and affected individuals of confidentiality incidents presenting a risk of serious injury, and maintain the required register. US state breach notification laws apply in parallel and we comply with them.
Where we act as a processor for a customer, we will notify that customer without undue delay and assist with their own notification obligations.
18. Children
The Services are not directed to and not available to individuals under 18, or under the age of majority in their jurisdiction if higher. We do not knowingly collect their personal information. If we learn that we have, we will delete it, subject only to records we are legally required to retain. Contact privacy@antonpayments.com if you believe a minor has provided information to us.
19. Third-party links
Our sites and documentation link to third-party services. We are not responsible for their practices. Review their policies before providing information to them.
20. Complaints
Contact our Privacy Officer first at privacy@antonpayments.com. We will investigate and respond in writing. If you are not satisfied, you may complain to:
- Canada: Office of the Privacy Commissioner of Canada, priv.gc.ca, 1-800-282-1376
- Quebec: Commission d'accès à l'information du Québec
- EEA: Your local supervisory authority, or the authority where our EU representative is established
- UK: Information Commissioner's Office, ico.org.uk
- California: California Privacy Protection Agency, or the Office of the Attorney General
- Other US states: Your state Attorney General
Nothing in this Policy limits your right to complain to a regulator or to pursue a remedy available to you by law.
21. Changes to this Policy
We review this Policy at least annually. When we make a material change we will update the version number and effective date, post the revised Policy here, notify account holders by email at least 30 days before it takes effect where the change materially reduces protections or expands our use of personal information, and make prior versions available on request from legal@antonpayments.com.
Continued use of the Services after the effective date constitutes acceptance of the revised Policy, except where applicable law requires your express consent, in which case we will ask for it.
Version history
| Version | Date | Summary |
|---|---|---|
| 1.0 | April 2026 | Initial policy |
| 2.0 | September 9, 2026 | Full binding policy. Added controller and processor roles, automated decision-making disclosure, entity resolution disclosure, model development commitments, named sub-processors, retention schedule, and regional annexes. |
22. Contact
Anton Payments Inc.
Attention: Privacy Officer
4145 N Service Road, 2nd Floor
Burlington, Ontario L7L 6A3, Canada
+1 (289) 246-7624
Privacy and rights requests: privacy@antonpayments.com
Legal and data processing agreements: legal@antonpayments.com
Security: security@antonpayments.com
Support: support@antonpayments.com
Trust centre: trust.antonpayments.com
© 2026 Anton Payments Inc.