How PAYMESE handles information
ICSP OÜ, registry code 16454909, is the controller for the PAYMESE website and marketplace during this release. This notice applies to public browsing, account profiles, listings, enquiries, deal rooms, documents, decisions, invoices and support communication.
Information we collect
We process signed-in identity data, business and authority details, listing and enquiry content, deal-room terms and decisions, document metadata and uploaded files, invoice and payment-status information, security events and technical logs. Public teasers exclude the private company and contact fields.
Why we use it
We use information to create and secure accounts, review anonymous listings, qualify enquiries, operate controlled introductions, preserve accepted term versions, manage documents and invoices, prevent misuse, respond to requests and meet accounting, claims, sanctions or other legal obligations. The legal basis depends on the activity and may be steps requested before a contract, performance of a contract, legitimate interests in operating a secure business marketplace, consent where requested, or compliance with law.
Controlled disclosure
PAYMESE does not publish account contact details. A counterparty receives company and contact information only after both parties accept the same current deal terms and PAYMESE releases the introduction. Uploaded files require a separate access decision. Service providers supporting hosting, storage, email, verification, accounting or professional advice receive only the information needed for their work.
International processing
A cross-border marketplace may involve providers or counterparties outside the EEA. Where GDPR transfer restrictions apply, PAYMESE uses an available lawful transfer mechanism and proportionate safeguards. A participant’s information is not released to a proposed counterparty merely because that person submits an enquiry.
Retention and security
Records are retained for the period needed to operate the account or deal and for applicable accounting, legal-claim, fraud-prevention and regulatory periods. Deal documents remain restricted to authorised users and can be removed from the room; a legal hold or mandatory retention duty may delay deletion. PAYMESE uses access controls, private storage, versioned acceptances, audit events and controlled document permissions, while no internet service can promise absolute security.
Your rights and contact
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection and may complain to the Estonian Data Protection Inspectorate or another competent authority. Submit a privacy request through your secure PAYMESE workspace or by written correspondence to the registered address below. We may need to verify identity and authority before acting.