MonduCard: Business credit card for SMBs and freelancers, with up to 45 days payment terms. Learn more.

Information pursuant to Article 13 and 14 General Data Protection Regulation for Buyers

Compliance with the General Data Protection Regulations is a high priority for our company. We would like to inform you below about the collection of your personal data by us.

Responsible entity

Mondu GmbH (Unter den Linden 16, 10117 Berlin, Germany) is an independent controller for checkout, eligibility, fraud prevention and risk assessment. It operates our checkout and processes buyer data for these purposes.

Mondu Financial Services B.V. (Herengracht 168, 1016 BP Amsterdam, Netherlands) is an electronic money institution and an independent controller for payment services, including the purchase of receivables and their management until any further assignment, payment postponement, card issuance and management, transaction processing, and related services.

Mondu Capital S.à r.l. (1, rue Jean Piret, L-2350 Luxembourg, registered with the Luxembourg Registre de Commerce et des Sociétés under number B265800) is an independent controller for the management, dunning and collection of receivables that have been further assigned to and are owned by it.

You can contact us at contact@mondu.ai. We will coordinate your request with the relevant controller.

Data we process

a) For the fulfillment of contractual obligations (Art. 6 para. 1 b p. 1 lit. b GDPR)

We collect personal data from you that is required for the verification and execution of the requested payment option, the communication in the context of the use of our services and the assignment of receivables. In addition to your company data and, if applicable, data on the owner, this also includes name, address, e-mail address, telephone number, URL, delivery and billing address, order data (such as currency, order details, shopping cart, purchase ID), industry and company form. Failure to provide this data may result in the agreement not being concluded.

Where you are a direct customer of Mondu (for example, MonduFlex or MonduCard), we additionally process data required for customer due diligence, including identity documents, beneficial ownership information, residential address of authorised representatives, and information about the financial situation of the business where requested. We also process payment amounts, fees, payment dates, and bank account data for settlement by direct debit where applicable.

For MonduCard specifically, we also process card application and verification data, transaction data (merchant name, transaction amount, date and time, location, currency, exchange rate data for foreign currency transactions), authentication data (including SCA results and security PIN data), device data (device identifiers, device integrity status, device registration data), digital wallet data, card delivery information, and cardholder support interactions.

b) To comply with legal obligations (Art. 6 para. 1 p. 1 lit. c GDPR)

We also process your personal data where this is necessary to comply with legal obligations to which we are subject. This includes in particular obligations under financial services, anti‑money laundering and sanctions regulations. For this purpose we may check whether buyers and other relevant persons are listed on official sanctions lists and must block or reject transactions where required by law.

For MonduFlex and MonduCard, where you are a direct customer of Mondu, this also includes customer due diligence and identity verification under the Dutch Anti-Money Laundering and Counter-Terrorist Financing Act (Wwft), ongoing monitoring of the business relationship including transaction monitoring and sanctions and PEP screening, record-keeping obligations, and suspicious transaction reporting to the relevant authorities.

Where we process biometric data for identity verification purposes in connection with MonduCard and MonduFlex, we do so on the basis of substantial public interest pursuant to Article 9(2)(g) GDPR, in connection with our obligations under the Wwft.

c) To protect our legitimate interests (Art. 6 para. 1 p. 1 lit. f GDPR)

Where necessary, we process your data beyond the actual performance of the contract to protect the legitimate interests of Mondu and third parties. This may include consulting credit agencies and public insolvency registers to determine and continuously monitor creditworthiness or default risks, as well as analyses for fraud prevention and risk assessment.

We also process personal data for the purpose of processing your requests. We may also process your data for receivables management, debt collection and for the assertion or defense of legal claims. In the event of default, we may share your data with debt collection agencies for the enforcement of outstanding amounts. Where a claim is passed to a debt collection agency, that agency acts as an independent controller. It may report the non-payment to credit agencies in its own right and is itself responsible for that processing. In addition, we and the financial institutions cooperating with us may transfer your personal data that we or the Merchant have collected in connection with the purchase of goods, as well as data on your creditworthiness, to banks and insurance companies for the purpose of refinancing.

For MonduCard, we also process your data for real-time transaction authorisation and fraud detection, monitoring card usage for security purposes, setting and enforcing spending limits, managing chargebacks and disputes, cardholder authentication, managing digital wallet provisioning, and complying with payment card network rules.

If you use the “Digital Trade Account” feature, we first automatically determine your “Purchasing Power” based on your creditworthiness data and our risk assessment with regard to default risks. We also transmit the Purchasing Power determined to the merchant with whom you use this feature. This is necessary to enable the merchant to display your Purchasing Power within the Digital Trade Account.

Where you access Mondu’s services through a marketplace platform, we carry out identity verification to prevent identity fraud, specifically to ensure that individuals accessing credit through Mondu are who they claim to be. This involves processing a copy of your identity document and a biometric facial image, compared against your identity document by automated means by a third-party identity verification provider. Biometric data is not retained beyond the period necessary to complete verification. This processing is based on our legitimate interest in preventing fraud and, for biometric data, on grounds of substantial public interest for fraud prevention under applicable national law (Art. 9(2)(g) GDPR). Completion of identity verification is required to access Mondu’s payment services through the marketplace platform.

Mondu will use the user’s email address to send advertising for Mondu’s own similar products or services, and will record whether those emails are opened and whether links in them are clicked in order to measure how the advertising performs (Art. 6 para. 1 p. 1 lit. f GDPR). The user may object to this use of their contact address and to this measurement at any time by sending a message to unsubscribe@mondu.ai or by clicking the unsubscribe link in Mondu’s advertising emails, without incurring any costs other than transmission costs at standard rates.

d) Based on your consent (Art. 6 para. 1 p. 1 lit. a GDPR)

If you have given us your consent to do so, we will process your contact data as well as data about your position in the company for advertising, including to send you advertising relevant to you by e-mail or telephone or for advertising campaigns on social media.

You can also provide us with your consent for data processing for the purpose of a preliminary check if you wish to check whether you are eligible to participate in the Buy Now Pay Later payment procedure. In this case, we process your personal data in order to make an automated decision about your creditworthiness. The data processed as part of the preliminary check includes your order data, further information on your financial history, your order history with third parties, creditworthiness data requested from credit agencies and data on devices used for fraud prevention, which may be exchanged with other third parties. If the preliminary check is positive, you can select Mondu as the payment method and we will continue to process your data on the basis of Art. 6 para. 1 lit. b) GDPR as described above. If the check is negative, you cannot select Mondu as a payment method and we will delete your data after 6 months at the latest or after you withdraw your consent.

Natural persons

Our services are aimed at businesses. We may process personal data of natural persons only where they are acting in their professional or business capacity in relation to a B2B transaction (e.g., sole proprietors, legal representatives, beneficial owners), and only to the extent necessary for creditworthiness or fraud‑risk assessment in the specific transaction.

Profiling and automated decision making

Using the received buyer data, including credit scores and credit-related data from credit agencies, Mondu conducts automated credit assessments to determine your eligibility for Mondu’s payment methods. The system analyses this alongside our own data and other available information to generate an automated decision (approval, rejection, or pending review). Cases flagged as pending undergo additional manual review by Mondu staff to reach a final determination.

We process company data and, where applicable, data on the owner or a natural-person contact, together with contact details, delivery and billing address, and order context (e.g. currency, items, purchase ID), plus verification results and internal risk signals. Depending on the outcome, certain payment methods may be unavailable, your Purchasing Power limit may differ, or your order may be flagged for manual review.

As part of this assessment, we use an AI-based tool to generate a fraud risk signal as one input into the overall automated decision. This AI component currently applies only where a buyer is being approved. The legal basis is our legitimate interest in fraud prevention.

For MonduCard services, we use automated decision-making for real-time transaction authorisation based on risk assessment, fraud detection that may result in transaction blocks, spending limit calculations, and digital wallet provisioning approvals.

You have the right to obtain human review of a decision, to express your point of view, and to contest the decision. To exercise these rights, contact dataprotection@mondu.ai.

Buyer account

We offer you the possibility to store your personal data in a buyer account. In this way, you can store your data once and access it in the context of orders without having to enter the information again, and instead use our “instant checkout” service. For this purpose, we require the following data as mandatory information: Company, first name, last name, address, e-mail address, birthday if applicable, account details, device data and password.

We use this data to create the buyer account and to confirm this to you, as well as to address you personally in the process. In addition, we also store your order history in your buyer account. You also have the option in your buyer account to manage your data, for example to update your contact details.

Data deletion

If there is no legal retention period, the data will be deleted as soon as storage is no longer necessary or the legitimate interest in storage has expired. The duration of storage depends, among other things, on the statutory retention obligations, e.g. from the German Fiscal Code or the German Commercial Code.

If your application has been rejected, we will store your data for a maximum period of 6 months.

Sources of data

In addition to data we collect directly from you, we may receive personal data from the following sources:

  • Credit agencies (listed below) providing creditworthiness information and credit scores
  • Public insolvency registers (in Germany, the portal for insolvency announcements published under Section 9 of the German Insolvency Code (InsO) at neu.insolvenzbekanntmachungen.de), from which we obtain information on insolvency events to monitor default risks and to register creditor claims in insolvency proceedings
  • Merchants providing order and transaction data
  • Visa providing transaction data, authorisation responses, and fraud-related alerts in connection with MonduCard transactions
  • GoCardless SAS providing account information (account details, balances, and transaction history for the past 90 days) where you have consented to the use of the open banking verification service.
  • LexisNexis Risk Solutions, providing an email-based fraud risk score derived from its global fraud network.
  • Contact-data providers, who supply updated contact details to keep our records accurate.

We process this data on the legal bases described above.

Recipients of your data

We share your data to the extent necessary for the provision of our services with financial institutions, insurance companies and credit agencies cooperating with us and, in the event of assignment of the receivable, to the new holder of the receivable, who acts as an independent controller for its management and recovery. Within the Mondu group this is typically Mondu Capital S.Ă  r.l.

If necessary, we use service providers who are strictly bound by instructions. They support us for example with platform hosting, fraud prevention, sanctions screening, customer relationship management, receivables management, debt collection, AI based text generation and the archiving and destruction of documents. We conclude separate contracts for order processing with these service providers.

We also share limited business customer information (such as company identification details and available credit limits) with selected merchant partners with whom you use our services, where this is necessary to operate co‑branded products or features (for example, to display your available credit or to manage benefits linked to your Mondu account). These merchants act as independent controllers and process the data under their own privacy notices.

When a payment is overdue, we may share relevant data with the marketplace platform operator through which your order was placed, for the purposes of supporting collections activity and restricting your access to Mondu as a payment option on that platform. This is based on our legitimate interest in recovering outstanding amounts and managing ongoing credit exposure.

Some recipients process data within the EEA or Switzerland and where necessary in third countries. In such cases we ensure an adequate level of data protection via an adequacy decision of the European Commission or appropriate safeguards such as Standard Contractual Clauses.

Credit agencies

We use credit agencies to obtain credit information for creditworthiness checks (see Automated decision-making). We share only the data necessary for the credit agency to identify the counterparty and return credit information (e.g. company name, legal form, address, relevant contact role where applicable, and order or account references). These agencies act as independent data controllers under their own privacy notices and legal bases. They retain this data under their own policies and applicable laws.

Where legally permitted and necessary for credit risk management, we may report data on non-contractual payment behaviour and subsequent enforcement actions (such as judicial dunning and enforcement measures) if a claim has not been settled or disputed in time. If you dispute a claim or identify an error, we suspend reporting while we review, and we promptly correct or update any data we have provided.

Our legal basis for credit agency queries and reports is Article 6(1)(f) GDPR, reflecting our legitimate interest in assessing payment risk. In accordance with Articles 12 et seq. GDPR, you are hereby informed about queries to credit agency databases, the transmission of personal data to credit agencies, and that these agencies process the transmitted data as independent controllers for their own purposes. Each credit agency processes data according to their respective privacy policies, which can be accessed via the links provided below.

We currently use the following credit agencies:

  • Creditsafe Deutschland GmbH: Creditsafe requires that we demonstrate and record our legitimate interest for each request and may conduct spot checks. Further details are available here.

  • infoscore Consumer Data GmbH: We obtain creditworthiness information, probability values (scores), and address deliverability verification from infoscore Consumer Data GmbH (Rheinstr. 99, 76532 Baden-Baden). Where legally permitted (and, for German data subjects, subject to the conditions of Section 31 BDSG), we may report data on non-contractual payment behaviour to them. Further information is available here.

  • SCHUFA Holding AG: For credit and creditworthiness checks we may request address and creditworthiness data including score values calculated using mathematical and statistical procedures. Recipients of SCHUFA information become controllers of the data they receive. Further information is available here.

  • Coface Information Services GmbH: We obtain creditworthiness information and debtor risk assessments from Coface. They may share received data with financial institutions and insurance companies within the Coface Group. Data subjects can contact coface_dpo@coface.com to exercise their rights. Further information is available here.

  • CRIF GmbH: We transmit personal data to CRIF for creditworthiness assessment. CRIF processes the received data for its own purposes including creating profiles, scoring and providing information to its contractual partners in the European Economic Area and Switzerland and where applicable other countries with an adequacy decision. We inform you under Article 14 GDPR that CRIF GmbH processes transmitted data as described here.

  • Dun and Bradstreet B.V.: We obtain business and risk information from Dun and Bradstreet. Further information and your rights are available here.

ID Verification

For MonduCard and MonduFlex, we use an identity verification service provider to carry out identity verification as required under the Wwft. This involves processing a copy of your identity document and a biometric facial image or video capture, compared against your identity document by automated means. Biometric data is not retained beyond the period necessary to complete the verification.

MonduCard

Marqeta Inc. (USA) acts as our card programme manager and processes data for card issuance, transactions, fraud prevention, digital wallet tokenisation, cardholder support, dispute management, and Strong Customer Authentication. All sensitive card data (PAN and CVV) is hosted exclusively by Marqeta and is not stored in or accessible to Mondu systems. For data transfers to Marqeta in the USA, we ensure an adequate level of data protection through Standard Contractual Clauses approved by the European Commission and additional technical and organisational security measures.

We also share data with Visa for transaction processing and authorisation. Visa acts as an independent controller for data it processes within its network. Mondu also receives transaction data from Visa as a Visa Principal Member. We share data with digital wallet providers (Apple, Google) for tokenisation services and with card fulfilment providers for the production and delivery of physical cards and activation materials.

Bank transfer payments (PayNow)

Where you choose to pay using the PayNow bank transfer option, we share the details necessary to initiate your payment with Token GmbH (EichhornstraĂŸe 3, 10785 Berlin, Germany), a payment institution authorised by BaFin. Token GmbH acts as an independent controller when it accesses your bank account to initiate the transfer. Our legal basis is Article 6(1)(f) GDPR.

Open banking (GoCardless)

Where we cannot assess your creditworthiness from available data, we may ask you to share your bank account information via an open banking service provided by GoCardless SAS (7 rue de Madrid, 75008 Paris, France), authorised by the ACPR (reference 17118) for account information services.

You will be redirected to your bank to authenticate yourself. GoCardless will then access, on your instruction, your account details, balances, and transaction history for the past 90 days. Access remains valid for up to 180 days. GoCardless shares this information with Mondu to assess your eligibility for our payment services.

GoCardless processes your account information as an independent data controller under its own Privacy Notice and End User Terms and Conditions. To withdraw your consent to GoCardless accessing your account, contact bank-account-data-support@gocardless.com.

Mondu’s legal basis for processing the account information received from GoCardless is our legitimate interest in assessing creditworthiness and payment risk before extending credit.

Fraud prevention (email risk scoring)

We share your email address, IP address and transaction identifiers with LexisNexis Risk Solutions FL Inc. (represented in the EU by LexisNexis Risk Solutions (Europe) Limited, Dublin) to obtain a fraud risk score. LexisNexis acts as an independent controller under its Emailage Processing Notice at https://risk.lexisnexis.com/corporate/processing-notices/emailage. Our legal basis is our legitimate interest in preventing fraud, Article 6(1)(f) GDPR. LexisNexis processes this data outside the EEA, including in the United States, where transfers are safeguarded by the EU-US Data Privacy Framework.

Dunning calls

Where a payment is overdue, we may contact you by telephone using an automated voice agent with a synthetic voice. We tell you this at the start of the call, and you can ask to speak to a member of our team instead.

We process your telephone number, call metadata, and the conversation itself. Our legal basis is our legitimate interest in recovering outstanding amounts, Article 6(1)(f) GDPR.

Twilio Inc. (USA) routes the call and acts as an independent controller under its own privacy notice. ElevenLabs Inc. (USA) operates the voice agent as our processor and does not use the data to train its models. Both process data in the United States under Standard Contractual Clauses. You can obtain a copy of these from dataprotection@mondu.ai.

Sale of overdue receivables

Where an amount remains unpaid, we may sell the receivable to a third party, including as part of a portfolio listed on a transaction platform. Potential investors may review relevant data about you to assess the portfolio, under confidentiality arrangements. The purchaser then becomes the new holder of the receivable. Our legal basis is our legitimate interest in recovering outstanding amounts (Article 6(1)(f) GDPR). Where an investor is outside the European Economic Area in a country without an adequacy decision, we rely on Standard Contractual Clauses.

Alibaba.com marketplace

Where you access Mondu’s services through the Alibaba.com marketplace, your personal data (including identity and contact details, business registration data, eligibility status, and payment outcome) is shared with Alibaba.com Singapore E-Commerce Private Limited (Singapore) and Alibaba.com Hong Kong Limited (Hong Kong), each acting as independent controllers. Alibaba uses this data to verify buyer identity, support payment eligibility enquiries, and manage order disputes on the Trade Assurance platform. Neither Singapore nor Hong Kong benefits from an adequacy decision by the European Commission. Transfers are therefore made on the basis of Standard Contractual Clauses under European Commission Implementing Decision 2021/914 (Module 1: controller to controller).

Your data protection rights

You can request information about your personal data processed by us. If your information is not (or no longer) accurate, you can request that your data be corrected. If your data is incomplete, you can request that it be completed. You have the right to request the deletion of your data. Please note that a claim for deletion depends on the existence of a legitimate reason. In addition, there must be no regulations that require us to retain your data. You have the right to request the restriction of the processing of your data. Please note that a right to restriction of processing depends on the existence of a legitimate ground.

Under certain conditions, you have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format or to request the transmission of this data to a third party. If the processing of your personal data is based on consent, you have the right to revoke the consent at any time, without giving reasons, for the future. The processing of the data until the revocation remains unaffected and is considered lawful. You have the right to object to the processing of your data on grounds relating to your particular situation.

Every data subject has the right to file a complaint with a supervisory authority if they believe that the processing of data concerning them violates data protection regulations.

Our Data Protection Officer

Our Data Protection Officer will be happy to provide you with more information about data protection under the following contact details:

Name: Jan Hagen Dip AML, CDPO, F.I.C.A
Email: dataprotection@mondu.ai
Address: Mondu Financial Services B.V., Attn: Jan Hagen, Herengracht 168, 1016 BP Amsterdam, Netherlands