Trust & Compliance Center

Popay
Compliance.

Keeping it chill·keeping it right.

The central hub for Popay's compliance policies and documentation. Log in for the full library, or explore the three domains below.

@popay.com account required
Three compliance domains

Everything we govern, in one place.

The portal is organised into three domains. Each one collects the policies, procedures, and commitments behind how Popay protects data, secures its systems, and operates ethically.

DOMAIN 01

GDPR & Privacy

We prioritize the protection of personal data in line with the General Data Protection Regulation. Explore our policies, procedures, and commitments to safeguarding your privacy.

  • Privacy & data protection policy
  • Data Processing Agreement (DPA)
  • Sub-processor register
  • Data subject request procedure
Log in to view GDPR documents
DOMAIN 02

ISMS & ISO 27001

Our Information Security & Management hub, dedicated to maintaining a robust Information Security Management System aligned with the ISO/IEC 27001 standard.

  • Information security policy
  • ISO/IEC 27001 certification programme
  • Access control & encryption standards
  • Incident response & business continuity
Log in to view ISMS documents
DOMAIN 03

ESG & Codes of Conduct

Reflecting our commitment to Environmental, Social, and Governance principles and ethical business practices. We strive for sustainability, employee wellbeing, and fair competition across our global operations.

  • Code of conduct & ethics
  • Supplier & anti-corruption policy
  • Sustainability & wellbeing commitments
  • Whistleblowing & fair competition
Log in to view ESG documents
What we commit to

Transparency and trust, by default.

These are the standing commitments behind every Popay product. Not aspirations — the controls we hold ourselves to today.

Data Protection Officer
Questions about how we handle personal data? Reach our DPO at gdpr@popay.com.
GDPR-compliant by default
Personal data handled in line with the GDPR from day one.
ISO/IEC 27001 aligned
A certified Information Security Management System.
100% EU data residency
Your data is stored and processed within the European Union.
DPA with every customer
A Data Processing Agreement signed as standard.
Transparent sub-processors
Our full sub-processor list is published and kept current.
Audit trail on access
Who accessed what, when — logged and reviewable.
Ethical & fair conduct
Anti-corruption, fair competition, and a clear code of conduct.
Incident disclosure
A defined process to detect, contain, and notify without delay.