PAYOUP

Compliance & Regulatory

Payoup is committed to maintaining the highest standards of regulatory compliance and data protection across all jurisdictions where we operate.

Last updated: September 2026

1. Overview

Payoup is a technology platform (SaaS) operated by Enexfi LTD that acts as the principal seller (Merchant of Record) on all transactions, providing service providers with the commercial, technical, and payment infrastructure to sell and grow globally. As a UK-registered technology company, we are committed to full compliance with all applicable regulatory requirements. Regulatory compliance is a core component of our corporate strategy.

Payoup is a technology platform that acts as the principal seller (Merchant of Record) on all transactions. All payment transactions are carried out by licensed third-party payment processors on behalf of Payoup as the billing entity; Payoup does not itself process payments, hold, or transmit funds. Payoup provides service providers with order management, invoicing, and supplier payment infrastructure.

2. Regulatory Framework

Payoup is a technology platform (SaaS) operated by Enexfi LTD, a company registered in the United Kingdom. The key regulatory frameworks we adhere to include:

  • United Kingdom: Companies Act and e-commerce regulations
  • European Union: GDPR and data protection directives
  • Consumer Protection: Distance selling and digital services regulations
  • International: KYC practices within FATF recommendation frameworks

3. AML & KYC

Payoup implements comprehensive policies to prevent money laundering and conduct customer due diligence:

  • All customers are required to undergo comprehensive KYC verification
  • Detection of suspicious activities through transaction monitoring systems
  • Regular risk assessments to prevent financial crimes
  • Regular screening against sanctions lists
  • Reporting of suspicious transactions to authorities

4. Data Protection

Personal data protection is one of the cornerstones of our compliance program:

  • Full compliance with GDPR and related data protection regulations
  • Data minimization: collecting only necessary data
  • Data security through AES-256 encryption
  • Effective management of data subject rights
  • Regular data protection impact assessments

5. UK Company Regulations and GDPR

Payoup maintains full compliance with UK company regulations and EU GDPR:

  • Operations as a UK-registered technology company
  • Secure transaction routing through licensed payment processors
  • Transparent pricing and platform terms
  • Regular platform audits and reporting
  • Independent security assessments

6. Industry Standards

Beyond legal requirements, we adopt best practices for platform security:

  • SSL/TLS encryption for all platform communications
  • ISO 27001-aligned information security practices
  • Regular third-party security audits
  • Regular penetration testing and security assessments

7. Audit and Reporting

The effectiveness of our compliance program is verified through regular audits:

  • Independent third-party audits
  • Regular internal audits
  • Periodic reporting to regulatory bodies
  • Monthly compliance reporting to the board of directors
  • Continuous compliance training programs

8. Incident Response and Reporting

Our rapid and effective incident response procedures are in place for compliance violations or security incidents:

  • Incident detection and reporting processes
  • Legal notification obligations to regulatory authorities
  • Timely notification to affected parties
  • Root cause analysis and corrective measures

9. Contact

Please contact us for questions about our compliance policy or regulatory requirements.

Compliance Contact

compliance@payoup.com
Enexfi LTD, 128 City Road, London, EC1V 2NX, UNITED KINGDOM