JustPayMe.ai

Privacy Policy

Effective date: 10 April 2026

Issued by Zild Ltd, trading as JustPayMe · Company no. 16351828 (England & Wales)

1. About Us

JustPayMe is a trading name of Zild Ltd, a company registered in England and Wales (company number 16351828). In this Privacy Policy, “we”, “us”, and “our” refer to Zild Ltd. The JustPayMe platform (“the Platform”) is accessible at justpayme.ai and helps businesses manage invoices, clients, and payment chase reminders.

We are committed to protecting personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy explains what personal data we collect, why we collect it, how we use it, and what rights you have.

2. Data Controller

Data controller
Zild Ltd, trading as JustPayMe
Company details
Zild Ltd — company no. 16351828, registered in England and Wales
Data enquiries
privacy@zild.me
General support
support@zild.me

3. Our Role: Controller and Processor

3.1 When we are the data controller

We act as data controller in respect of your account and registration data (name, email, phone, business name), your billing and subscription data, and usage and technical data collected automatically when you use the Platform.

3.2 When we are a data processor

When you enter your clients' personal data into the Platform — such as names, email addresses, phone numbers, and postal addresses — you are the data controller for that data. We process it solely on your documented instructions (for example, to send chase reminders on your behalf).

As a data processor in this context, we:

  • Act only on your instructions
  • Do not use your clients' data for any purpose other than delivering the service you have requested
  • Impose equivalent obligations on our sub-processors (see Section 9)
  • Notify you promptly of any personal data breach affecting your clients' data
  • Delete or return your clients' data on termination of your account in accordance with Section 11

The terms governing our role as data processor are set out in Schedule 1 (Data Processing Agreement), which forms part of our Terms of Service.

You are responsible for ensuring that you have a lawful basis under UK GDPR to share your clients' personal data with us and to instruct us to contact them on your behalf.

4. Chase Reminders and Your Clients

When you instruct us to send a payment chase reminder to one of your clients via email, SMS, or WhatsApp, the message is sent by Zild Ltd on your behalf using our technology infrastructure. The following points are important:

  • Your client is receiving a communication from you, facilitated by our platform
  • The lawful basis for processing your client's data rests with you as the data controller
  • You must ensure that any contact details you enter are accurate and that you are authorised to contact the individual
  • JustPayMe will identify itself as the sending platform where technically required or appropriate
  • We do not contact your clients for any purpose other than as you instruct us

5. What Data We Collect

5.1 Account data: Name, email address, phone number, and business name provided during registration and onboarding.

5.2 Client data (processed on your behalf): Names, email addresses, phone numbers, and postal addresses of your clients that you enter into the Platform.

5.3 Billing data: Invoice amounts, due dates, descriptions, payment status, and currency information.

5.4 Communication data: Records of chase reminders sent via email, SMS, and WhatsApp on your behalf, including delivery status and responses.

5.5 Integration data: Where you connect a third-party accounting platform (such as Xero, Sage, or QuickBooks), we receive invoice and contact data from that platform to sync with your account.

5.6 Usage data: Pages visited, features used, and interaction patterns collected through analytics tools (Amplitude).

5.7 Technical data: IP address, browser type, device information, and error logs collected automatically.

5.8 Payment data: Subscription and billing transactions are processed by Stripe. Payment card details are entered directly into Stripe's secure interface and are never transmitted to, or stored on, Zild Ltd's systems.

6. How We Use Your Data

  • Service delivery: Managing your account, invoices, clients, and chase reminders
  • Communication: Sending chase reminders to your clients via email (SendGrid), SMS, and WhatsApp (Twilio) on your behalf
  • Accounting integrations: Syncing data with connected platforms at your direction
  • Analytics: Understanding usage patterns to improve the Platform
  • Customer support: Responding to your queries and resolving issues
  • Security and fraud prevention: Detecting and preventing misuse
  • Legal obligations: Complying with applicable laws and regulations

7. Legal Basis for Processing

Contract (Article 6(1)(b)): Processing necessary to provide the JustPayMe service, including account management, service delivery, and billing.

Legitimate interests (Article 6(1)(f)): Analytics, service improvement, security, and fraud prevention, where our interests are not overridden by your rights.

Legal obligation (Article 6(1)(c)): Processing required by law, such as financial record-keeping.

Consent (Article 6(1)(a)): Where we rely on consent — for example, for optional analytics cookies — we will make this clear. You may withdraw consent at any time.

8. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals, as described in Article 22 of the UK GDPR. The Platform does not score, rank, or make automated decisions about your clients.

9. Third-Party Services and Sub-processors

We use the following third-party providers. We do not sell personal data to any third party.

Auth0 (Okta)
Authentication and identity management
Amazon Web Services
Cloud hosting — EU-West-2 (London, UK)
SendGrid (Twilio)
Email delivery for chase reminders
Twilio
SMS & WhatsApp message delivery
Stripe
Subscription billing (card data goes directly to Stripe)
Amplitude
Product analytics — EU data residency
Sentry
Error monitoring and diagnostics
Xero / Sage / QuickBooks
Accounting integrations (when you connect them)

10. International Transfers

Your data is primarily stored and processed in the UK and EU, using AWS infrastructure in EU-West-2 (London). Several providers are headquartered in the US and may process data there. We ensure appropriate safeguards are in place, including the UK Addendum to the EU Standard Contractual Clauses or other UK-approved transfer mechanisms.

11. Data Retention

Account and profile data
Active account; deleted within 30 days of account deletion
Client and billing data
Active account; deleted within 30 days of account deletion
Communication logs
Retained 90 days after sending, then deleted
Usage and analytics data
Anonymised and aggregated; retained indefinitely
Legal and financial records
Retained as required by law (typically 6 years)

12. Data Security

  • Encryption in transit (TLS/HTTPS) and at rest (AES-256)
  • Database hosted in AWS EU-West-2 (London) with restricted access
  • Authentication via Auth0 with industry-standard security
  • Access controls limiting data access to authorised personnel
  • Regular security reviews and vulnerability assessments

13. Data Breach Notification

In the event of a personal data breach, we will assess the risk, notify the ICO within 72 hours where required under Article 33 UK GDPR, notify you without undue delay if a breach affects data you have entrusted to us, and notify affected individuals directly where required under Article 34 UK GDPR.

14. Your Rights

Access
Request a copy of your personal data
Rectification
Ask us to correct inaccurate data
Erasure
Request deletion of your data
Restriction
Ask us to limit how we process your data
Portability
Receive your data in a machine-readable format
Objection
Object to processing based on legitimate interests
Withdraw consent
Where processing is consent-based, withdraw at any time

To exercise any of these rights, contact us at privacy@zild.me. We will respond within one calendar month.

15. Cookies

Essential cookies: Strictly necessary for the Platform to function (session token via Auth0, CSRF protection). Cannot be disabled.

Analytics cookies: We use Amplitude to understand usage patterns (EU data residency). Analytics cookies are non-essential — we obtain your consent before setting them via a cookie consent banner. You may withdraw consent at any time.

No advertising or tracking cookies: We do not use advertising cookies, tracking pixels, or any cookies that monitor your activity across other websites.

For full details, see our Cookie Policy.

16. Children

JustPayMe is a business-facing platform and is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.

17. Marketing Communications

We do not currently send marketing communications. If we introduce them in the future, we will carry them out in compliance with PECR and UK GDPR, obtaining consent where required and providing a clear mechanism to opt out.

18. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and/or a prominent notice within the Platform. Minor changes will be updated on this page with a revised effective date.

19. Complaints

If you have a concern, please contact us first at privacy@zild.me. If you remain dissatisfied, you may lodge a complaint with the Information Commissioner's Office (ICO):

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk · Helpline: 0303 123 1113

Schedule 1 — Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Zild Ltd (“Processor”) and the user of the JustPayMe platform (“Controller”).

1. Subject Matter

The Processor shall process personal data for the purpose of providing the JustPayMe service, including storing client contact data, sending payment chase reminders via email, SMS, and WhatsApp, syncing data with connected accounting platforms, and maintaining communication logs.

2. Categories of Data

Data subjects: Clients of the Controller. Categories: names, email addresses, phone numbers, postal addresses, invoice and payment information, communication history.

3. Obligations of the Processor

  • Process personal data only on documented instructions from the Controller
  • Ensure authorised persons are bound by confidentiality
  • Implement appropriate technical and organisational security measures
  • Not engage a sub-processor without prior authorisation (general authorisation granted for sub-processors listed in Section 9)
  • Notify the Controller without undue delay of any personal data breach
  • Assist the Controller in responding to data subject requests
  • Assist with obligations under Articles 32–36 UK GDPR (security, breach notification, DPIAs, prior consultation)
  • Delete or return all personal data after end of service

4. Obligations of the Controller

The Controller warrants it has a valid lawful basis for processing, the data provided is accurate, required notices have been given to data subjects, and it will comply with its obligations as data controller under UK GDPR.

5. Sub-processors

The Controller grants general authorisation for sub-processors listed in Section 9. The Processor shall impose equivalent obligations, provide notice of changes, and remain liable for sub-processor performance.

6. International Transfers

The Processor shall not transfer personal data outside the UK or EEA without appropriate safeguards as set out in Section 10.

7. Audit Rights

The Processor shall allow audits on reasonable written notice (no less than 30 days). The Controller may exercise this right no more than once per calendar year.

8. Term

This DPA remains in force for the duration of the Terms of Service. Upon termination, the Processor shall delete or return all personal data within 30 days, except where retention is required by law.

9. Governing Law

This DPA is governed by the laws of England and Wales.

Zild Ltd, trading as JustPayMe · Company no. 16351828
privacy@zild.me · support@zild.me · justpayme.ai

Product

  • Pricing
  • Help Center

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy

Support

  • Help Center
  • Contact

Company

  • About us
  • England & Wales

© 2026 Zild Ltd trading as JustPayMe. All rights reserved.