
● Administering and operating the MEZZA Services, including account management and service
delivery;
● Communicating with you regarding your transactions, account security, and updates to our
services;
● Sending marketing communications and promotional offers, subject to your choices;
● Understanding trends, improving our services, and assessing the effectiveness of our marketing
and advertising;
● Personalizing your user experience, including offers and recommendations;
● Conducting surveys and requesting feedback;
● Supporting advertising and promotional activities, including targeted advertising;
● Processing referrals, gifted credits, and related transactions;
● Collaborating with our Merchant Partners to improve their services and identify VIP customers;
● Ensuring the security of our services, preventing fraud, and protecting MEZZA’s rights and the
rights of others;
● Carrying out activities at your request and with your consent;
● Using de-identified and aggregated data for research, analytics, and lawful business purposes.
Your personal data will be retained only for as long as necessary to fulfil the purposes for which it was
collected, plus any applicable statutory limitation periods.
You have the following rights: access, rectification, erasure, restriction of processing, objection, and data
portability. You may exercise these rights by contacting us at: privacy@mezzapay.com.
You also have the right to lodge a complaint with the French supervisory authority (CNIL).
22.2 Subprocessing and Data Protection
In connection with the performance of this Agreement, the Processor is authorized to process, on behalf
of MEZZA, only the personal data strictly necessary for the agreed purposes, which may include account
management, payment processing, transaction facilitation, analytics, marketing support, customer
communications, fraud prevention, and service improvement.
The Processor undertakes to:
1. Process personal data solely on documented instructions from MEZZA, including with respect to
transfers to a third country, unless required to do so by law;
2. Ensure the confidentiality of personal data and guarantee that any person authorized to process it
is bound by an appropriate confidentiality obligation;
3. Implement appropriate technical and organizational measures to ensure the security of personal
data;
4. Assist MEZZA in fulfilling its obligations regarding data subjects’ rights and personal data
breach notifications;
5. Upon completion of the services, delete or return all personal data in accordance with MEZZA’s
instructions;
6. Make available to MEZZA all information necessary to demonstrate compliance with the GDPR
and the Loi Informatique et Libertés, and allow for and contribute to audits conducted by MEZZA
or its designated auditor.