This Privacy Policy explains how MATTECH OÜ, trading as GuardRailPay (“GuardRailPay”, “MATTECH”, “we”, “us” or “our”), collects, uses, stores and shares personal data in connection with the GuardRailPay website, platform, applications, communications and related services (together, the “Service”).
GuardRailPay is primarily a business-to-business service. It is designed for companies, accountants, bookkeepers and other persons acting in a professional or business capacity.
1. Who we are
MATTECH OÜ
Estonian registry code: 17589238
Registered office: Narva mnt 86-3, Kesklinna linnaosa, Tallinn, Harju maakond, 10150, Estonia
Trading name: GuardRailPay
Website: guardrailpay.com
Privacy and legal enquiries: legal@guardrailpay.com
MATTECH OÜ is established in Estonia and is subject to applicable Estonian and European Union data protection law, including the EU General Data Protection Regulation (“EU GDPR”). Where the UK GDPR applies because we offer the Service to, or monitor relevant activity of, individuals in the United Kingdom, we also comply with the UK GDPR and the Data Protection Act 2018 as amended, including by the Data (Use and Access) Act 2025.
Where required by law, details of our appointed United Kingdom representative will be published in this Privacy Policy and on our website.
2. Our role: controller and processor
Our role depends on the context.
2.1 Where MATTECH is a controller
We generally act as a controller for personal data used to:
- create and administer GuardRailPay user accounts;
- manage subscriptions, billing and payments;
- provide customer support;
- operate security, fraud prevention and service monitoring;
- run our referral programme;
- manage our own sales, marketing and business development;
- manage our website and analytics;
- comply with legal, tax, accounting and regulatory obligations;
- establish, exercise or defend legal claims.
2.2 Where MATTECH is a processor
When a business customer uploads or forwards invoices, provides debtor or customer contact details, or uses GuardRailPay to send invoice follow-up communications, the business customer normally determines why that personal data is processed and is the controller. MATTECH processes that data on the customer’s documented instructions and normally acts as a processor.
Examples may include:
- names and work contact details of the customer’s customers or debtors;
- invoice information;
- invoice attachments;
- customer correspondence;
- payment promises;
- payment confirmation messages;
- notes added by authorised users.
Where we act as a processor, the relevant business customer is responsible for its own lawful basis, privacy information and relationship with the individuals whose data it provides to GuardRailPay. Our Data Processing Terms form part of the GuardRailPay Terms of Service.
3. Personal data we collect
Depending on how you interact with GuardRailPay, we may collect the following categories of personal data.
3.1 Account and profile data
- name;
- work email address;
- job title or role;
- company name;
- login and account identifiers;
- team membership and permissions;
- authentication and account security information.
3.2 Company and subscription data
- business name and business contact details;
- company role;
- subscription plan;
- usage level;
- billing status;
- subscription dates;
- invoices issued by MATTECH;
- tax or company details supplied for billing.
3.3 Payment data
Payments are processed through third-party payment providers such as Stripe. We may receive:
- payment status;
- payment method type;
- partial card information such as brand and last four digits;
- billing address;
- transaction identifiers;
- fraud and risk indicators;
- dispute or chargeback information.
We do not need to store full payment card numbers or security codes in GuardRailPay.
3.4 Service content
Where a customer uses the Service, the platform may process:
- invoice PDFs, images and other invoice files;
- invoice number;
- issue date and due date;
- amount and currency;
- customer or debtor name;
- customer or debtor business email address;
- payment terms;
- correspondence relating to an invoice;
- payment promises;
- payment confirmations;
- internal notes;
- status history and audit events.
3.5 Email and communication data
We may process:
- email sender and recipient addresses;
- subject lines;
- email message bodies;
- attachments;
- message identifiers;
- delivery, bounce and complaint status;
- replies;
- support communications.
3.6 Referral programme data
If you use Invite & Earn, we may process:
- referral identifier;
- referral link activity;
- referred company;
- referral attribution;
- subscription status of the referred company;
- commission calculations;
- commission ledger;
- payout status;
- Stripe Connect account identifier;
- fraud and risk signals associated with referral payouts.
3.7 Website, device and technical data
We may collect:
- IP address;
- browser type;
- device type;
- operating system;
- approximate location derived from IP address;
- session identifiers;
- login history;
- pages and features used;
- timestamps;
- diagnostic and security logs;
- cookie and similar technology identifiers.
3.8 Sales and business-contact data
For business development we may process professional contact information such as:
- name;
- employer;
- role or job title;
- business email address;
- business website;
- company size or sector;
- publicly available professional information;
- campaign and response history;
- opt-out and suppression status.
Sources may include:
- the individual or their employer;
- public company websites;
- public business registers;
- professional directories;
- business data providers;
- referral partners;
- publicly available professional sources.
We do not intentionally collect personal data from private or personal sources for business outreach.
4. Data we do not want you to upload
GuardRailPay is not designed for the routine processing of special-category personal data or criminal-offence data.
Customers should not upload information about health, racial or ethnic origin, political opinions, religion, trade-union membership, genetic or biometric data used for unique identification, sexual orientation, sexual life, or criminal convictions unless it is genuinely necessary, lawful and expressly permitted under the customer’s agreement with us.
Do not use GuardRailPay to store secrets, passwords, authentication credentials or unrelated personal records inside invoice notes or attachments.
5. How we use personal data and our lawful bases
Where we act as controller, we rely on one or more of the following lawful bases.
5.1 Contract and steps before contract
We process data where necessary to:
- create and administer an account;
- provide the Service;
- manage subscriptions;
- process requested referrals and payouts;
- respond to contractual support requests;
- enforce the Terms of Service.
5.2 Legitimate interests
We may process personal data where necessary for our legitimate interests or those of a third party, provided those interests are not overridden by the individual’s rights and freedoms.
Our legitimate interests may include:
- operating and improving the Service;
- keeping the Service secure;
- preventing fraud, abuse and unauthorised access;
- maintaining business records;
- measuring product usage;
- communicating with business contacts;
- promoting GuardRailPay to appropriate business organisations;
- managing referrals;
- preventing duplicate, invalid or abusive commission claims;
- establishing and defending legal claims.
5.3 Legal obligation
We process data where necessary to comply with:
- tax and accounting obligations;
- anti-fraud and financial compliance requirements;
- lawful requests from regulators, courts or public authorities;
- data protection obligations;
- record-keeping duties.
5.4 Consent
Where the law requires consent, for example for certain cookies or specific forms of electronic marketing, we request consent before carrying out that processing.
You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing already carried out.
6. Business-to-business marketing
GuardRailPay may contact relevant business organisations and professional contacts about the Service.
Where UK rules apply:
- we distinguish between corporate subscribers and individual subscribers where required by the Privacy and Electronic Communications Regulations 2003 (“PECR”);
- where consent is legally required for electronic marketing, we will obtain it or rely on another permitted basis;
- where UK GDPR applies to personal business-contact data, we rely on an appropriate lawful basis, which may include legitimate interests;
- every recipient may object to direct marketing at any time.
You have an absolute right to object to the use of your personal data for direct marketing.
You can opt out by using an unsubscribe link where provided or contacting legal@guardrailpay.com.
We maintain suppression records so that we can respect opt-out requests. A minimal suppression record may be retained even after other marketing data is deleted.
7. Invoice reminder communications
GuardRailPay may send payment-reminder and invoice-follow-up emails on behalf of a business customer.
The customer, not MATTECH, is responsible for deciding:
- who should receive an invoice or reminder;
- whether the recipient’s contact details are accurate;
- whether the underlying invoice is valid;
- whether there is a lawful basis for the communication;
- whether a communication must stop because of a dispute, legal restriction or other circumstance.
GuardRailPay may process replies automatically to identify operational information such as:
- payment expected on a particular date;
- payment already made;
- request for a copy of an invoice;
- dispute or query requiring human attention.
8. Automated processing and artificial intelligence
We may use automated systems, including machine-learning or artificial-intelligence services, to:
- extract information from invoices;
- classify customer replies;
- identify payment promises;
- identify payment confirmations;
- route messages for review;
- detect technical or fraud risks.
These tools support administrative workflow. GuardRailPay is not designed to make solely automated decisions that produce legal or similarly significant effects on an individual.
Automated outputs may be incorrect. Customers remain responsible for reviewing information where appropriate and for decisions relating to their own customers, debts, contracts and legal rights.
9. Who we share data with
We may share personal data with service providers that support the operation of GuardRailPay, including providers of:
- cloud hosting and application infrastructure;
- database and authentication services;
- secure file storage;
- email delivery and inbound email processing;
- payment processing;
- payout services;
- fraud prevention;
- analytics and monitoring;
- customer support;
- artificial-intelligence and document-processing services;
- professional legal, accounting, audit and insurance services.
Our current technology stack may include providers such as Stripe, Supabase, Railway, Vercel, Cloudflare, Resend and OpenAI or equivalent replacements.
We may also disclose personal data:
- where required by law;
- to courts, regulators or competent authorities;
- in connection with an actual or proposed merger, acquisition, financing, reorganisation or sale of all or part of the business, subject to appropriate confidentiality safeguards;
- where necessary to establish, exercise or defend legal claims.
We do not sell personal data to data brokers.
10. Subprocessors
Where MATTECH acts as a processor for a business customer, we may appoint subprocessors to provide parts of the Service.
We require subprocessors to protect personal data under written terms appropriate to the processing.
A current list of material subprocessors may be made available at guardrailpay.com/subprocessors or on request.
11. International transfers
MATTECH is established in Estonia and may use service providers located in or accessible from countries outside the European Economic Area or the United Kingdom.
Where an international transfer requires a safeguard, we use an appropriate lawful transfer mechanism, which may include:
- an adequacy decision or adequacy regulations;
- the European Commission Standard Contractual Clauses;
- the UK International Data Transfer Agreement or UK Addendum;
- an applicable Data Privacy Framework mechanism;
- another legally permitted safeguard.
The exact mechanism depends on the origin, destination and provider involved.
You may contact legal@guardrailpay.com for further information about relevant transfer safeguards.
12. Data retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security, dispute-resolution and enforcement purposes.
Our general retention approach is:
Account and company data
For the life of the account and for a reasonable period afterwards where needed for contractual, security or legal purposes.
Customer Content processed on behalf of customers
Normally for the duration of the customer’s subscription or until deleted by an authorised customer, followed by deletion from active systems after termination in accordance with our operational retention cycle. Residual encrypted backup copies may remain for a limited backup-retention period before being overwritten.
Billing, commission and accounting records
Generally retained for at least the period required by applicable Estonian accounting and tax law. Certain accounting and transaction records may need to be preserved for seven years.
Security and technical logs
Kept for a period reasonably necessary for security, debugging, fraud prevention and audit purposes.
Support records
Kept for as long as reasonably required to resolve the request and manage legal or service issues.
Direct marketing data
Kept while relevant to our business relationship or legitimate marketing activity. Opt-out and suppression information may be retained longer so we do not contact you again contrary to your request.
Legal claims
Relevant records may be retained for the applicable limitation period and for as long as reasonably necessary to establish, exercise or defend a claim.
We may retain anonymised or aggregated information that no longer identifies an individual.
13. Security
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration, disclosure or destruction.
Measures may include:
- access controls;
- role-based permissions;
- authentication controls;
- encryption in transit;
- private storage;
- audit logs;
- restricted production access;
- monitoring;
- backups;
- incident-management procedures.
No internet service can guarantee absolute security.
Customers are responsible for maintaining the confidentiality of their login credentials, limiting access to authorised users, using appropriate device security and promptly removing users who no longer require access.
14. Your data protection rights
Depending on the law that applies and the circumstances, you may have rights to:
- access your personal data;
- correct inaccurate personal data;
- request deletion;
- restrict processing;
- object to processing;
- object to direct marketing;
- receive certain personal data in a portable format;
- withdraw consent where processing is based on consent;
- complain to a competent supervisory authority.
These rights are not absolute. Legal exemptions or retention obligations may apply.
If MATTECH processes your data only as a processor for a GuardRailPay business customer, we may need to refer your request to that customer or assist that customer with the request.
To exercise a right, contact legal@guardrailpay.com. We may need to verify your identity before acting on a request.
15. Data protection complaints
You may complain to us at legal@guardrailpay.com.
Where UK GDPR applies, we will handle data protection complaints in accordance with applicable UK law, including applicable complaint-handling requirements introduced or amended by the Data (Use and Access) Act 2025.
You also have the right to complain to a supervisory authority.
For MATTECH’s establishment in Estonia, the competent supervisory authority may be:
Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Tatari 39
10134 Tallinn
Estonia
Where UK GDPR applies, you may also have the right to complain to the Information Commissioner’s Office (ICO).
We encourage you to contact us first so we have an opportunity to address the issue.
16. Cookies and similar technologies
GuardRailPay may use:
Strictly necessary technologies
Needed for login, authentication, security, load balancing, fraud prevention and core service operation.
Functional technologies
Used to remember settings or improve service functionality.
Analytics technologies
Used to understand how the website and product are used and to improve performance.
Marketing technologies
Used only where implemented and lawfully permitted.
Where consent is required under applicable law, we will request consent before using non-essential technologies. Where UK law permits certain low-risk cookies without consent, we may rely on that permission subject to applicable safeguards.
17. Children
GuardRailPay is a business service and is not directed to children.
Users must be at least 18 years old and have authority to act for the relevant business.
We do not knowingly offer GuardRailPay to children.
18. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in the Service, law, technology or business operations.
Where a change materially affects how we use personal data, we will take reasonable steps to bring the change to the attention of affected users before or when it takes effect, where required by law.
The “Last updated” date at the top shows the latest revision.
19. Contact
For privacy questions, rights requests or complaints:
MATTECH OÜ / GuardRailPay
Registry code: 17589238
Narva mnt 86-3
Kesklinna linnaosa, Tallinn
Harju maakond, 10150
Estonia
Email: legal@guardrailpay.com