Last updated: September 11, 2026
moon-mongoose is committed to compliance with the General Data Protection Regulation. We recognize the importance of protecting personal data and respecting the rights of individuals within the European Economic Area and the United Kingdom.
We process your personal data under the following legal bases:
You have the following rights regarding your personal data:
You can request confirmation of whether we process your personal data and obtain a copy of that data. We will provide this information in a commonly used electronic format.
If your personal data is inaccurate or incomplete, you have the right to request correction or completion of that information.
Under certain circumstances, you can request deletion of your personal data. This right applies when data is no longer necessary for its original purpose, when you withdraw consent, or when processing is unlawful.
You may request that we restrict processing of your personal data in specific situations, such as when you contest the accuracy of the data or object to processing.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another data controller.
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month, though this period may be extended by two additional months for complex requests.
For questions about how we handle your personal data or to lodge a complaint, you may contact our data protection officer at [email protected].
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority in your country of residence or where the alleged infringement occurred.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.
When we transfer your personal data outside the EEA or UK, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission or adequacy decisions.
Our fraud detection services use automated processing to analyze transaction patterns. However, decisions with significant effects are subject to human review. You have the right to request human intervention and to challenge automated decisions.
We retain personal data only as long as necessary for the purposes for which it was collected or as required by law. Specific retention periods depend on the type of data and legal requirements applicable to our services.
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website or directly to you.