Security Is Our Highest Investment
- Licence number
- No. 18
- Issuing authority
- Bank of Lithuania
- Legal entity
- UAB Nexpay — reg. code 304708124
Compliance
European regulation
Nexpay operates in accordance with key European Union regulations that govern data protection, operational resilience, payment services, and financial crime prevention, ensuring a consistent compliance framework across the EU.
National laws
Nexpay complies with applicable national legislation in the jurisdictions where it operates or provides regulated services.
Payment processing standards
Nexpay follows established European payment scheme rules to ensure secure, reliable, and interoperable payment processing.
Sanctions compliance
Nexpay maintains a comprehensive sanctions compliance framework to prevent prohibited transactions and mitigate financial crime risks.
Subprocessors
Subprocessors are listed by category rather than by name. Contractual confidentiality obligations prevent us from publicly disclosing the identity of individual providers. The full, named list is available to clients, prospective clients, and counterparties on request: write to [email protected].
Encryption in transit
Data locking at rest
Platform uptime
Our commitment
We operate an information security management system (ISMS) aligned with the NIST Cybersecurity Framework and designed to meet the Digital Operational Resilience Act (Regulation (EU) 2022/2554), its regulatory technical standards, and the requirements of the Bank of Lithuania.
- NIST Cybersecurity Framework
- ISMS design baseline
- DORA — Regulation (EU) 2022/2554
- Including regulatory technical standards
- Bank of Lithuania requirements
- Supervisory expectations for EMIs
Governance and accountability
Ownership of ICT risk sits with the Management Board, with independent oversight and audit.
The Management Board bears ultimate responsibility for ICT risk, approves the security policy and digital operational resilience strategy, allocates the resources needed to implement them, and receives an annual security posture report.
A dedicated Chief Information Security Officer oversees the ISMS, and control and audit functions are organised on the three-lines-of-defence model.
The information security policy is binding on all staff, contractors and ICT service providers, and is reviewed at least annually and after any major incident, significant audit finding or supervisory instruction.
How we protect information
Ten control domains make up the ISMS. Each is documented, assigned an owner, and reviewed on a defined cycle.
Security incidents are handled under a documented incident management plan with defined severity levels and response times. Incidents classified as major under DORA are reported to the competent authority within the regulatory deadlines, and affected clients are informed where required by law or by our agreements with them.
Compliance with DORA, GDPR (overseen by our Data Protection Officer) and applicable Bank of Lithuania requirements is assessed and documented at least annually.
If you believe you have found a security vulnerability or incident affecting Nexpay systems, please contact us at [email protected]. We ask that you do not access, modify or disclose data beyond what is needed to demonstrate the issue.
Privacy overview
Your rights over your data
Under this framework, clients are granted specific rights to manage and audit their personal data, though certain financial compliance laws may restrict their immediate execution.
You can request a clear, comprehensive copy of all personal data stored about you by the company.
You can demand your automated, contract-based data be provided in a structured, machine-readable format to move to another controller.
You can instantly update basic contact info via your dashboard, or modify restricted records (like legal name or financial details) by contacting [email protected].
You can contest data processing justified by “legitimate interests” or completely block the use of your data for direct marketing.
You can ask the company to temporarily freeze the processing of your data, though doing so may pause your ability to use the services.
You may request the deletion of your data when there is no logical reason for its processing. However, statutory Lithuanian compliance laws supersede this right, legally forcing the company to retain identification/verification data for eight years and transaction histories for five years post-account closure.