C T Bikes Limited Privacy United Kingdom
Version 1 (June 2026)
Introduction
C T Bikes Limited is a trading name of C T Bikes Limited . At Dojo, we are committed to respecting your privacy.
Personal data is any information which relates to an individual. This Privacy Policy outlines how and why we process personal data in connection with our payment services and on this website.
Whenever we say ‘we’ in this Privacy Policy, we mean the C T Bikes Limited providing you with a product or service. That company is known as a Bike Company in relation to the relevant personal data processing activities.
C T Bikes Limited is the relevant data controller in relation to the activities covered in this Privacy Policy
In this Privacy Policy:
Merchant means any customer of our payment services.
Your information means any of your personal data processed in connection with our payment services on this website.
2. How do I get in touch with you?
If you have any questions about this Privacy Policy or how we handle your data and privacy, please contact us at dataprotection@dojo.tech or by phone on 0161 917 6667 in the UK . You can contact us to exercise your rights by emailing ctbikes_15@yahoo.com . Our DPO is accessible from that inbox.
You have the right to make a complaint to the ICO (www.ico.org.uk) or or, if you are based in the EEA, the relevant supervisory authority for the signatory state in which you are based (https://www.edpb.europa.eu/about-edpb/about-edpb/members_en). We would, however, appreciate the chance to deal with your concerns in the first instance, so please contact us at ctbikes_15@yahoo.com or by phone on 0161 917 6667
Who does this Privacy Policy apply to?
This Privacy Policy applies to several categories of individuals whose personal data is processed in connection with the provision of our payment services and on this website:
Any sole trader or individual in an unincorporated partnership which is a merchant or prospect (if you are in this category, we refer to you in this Privacy Policy as a Sole Trader or Individual at a Partnership).
Any cardholder or consumer whose information is processed on our website or otherwise through our payment services (Consumer).
Any visitor to, or user of, this website, any of our or our group companies’ websites or any web or mobile application (Visitor).
In this Privacy Policy, ‘you’ refers to the relevant category of individual above, as the context requires.
What information do we collect from you?
Direct information
If you are a Sole Trader, Individual at a Partnership or Merchant Representative, you may provide information directly to us, for example by the way you communicate or do business with us, such as:
General information (including name and address and contact details ).
Contact information (including your physical and e-mail address and phone number).
Account details (username and other credentials used to log in to our website and application).
Direct financial information (including your bank details).
Market research and competition information (including information you provide about your opinions of our products and services).
Indirect information
If you are a Sole Trader, Individual in a Partnership or Merchant Representative, we may also indirectly collect certain information, which may include:
Geolocation information (including where you use our products and services where we can detect this through a device in some contexts).
If you are a Consumer, the information we require, and collect, to give effect to a transaction at a merchant, includes:
Your card details and associated information held by your card issuer which we need to give effect to any transaction.
Information about the transaction, such as the merchant and amount spent.
Other information which may be provided to ensure we can facilitate transactions for you, including (where relevant) your name, physical and e-mail address, phone number and other book-keeping and other information required for legal and regulatory purposes.
If you are a Consumer, we may also infer personal data about you based on: (i) the personal data that you have provided directly to us; and (ii) the personal data that we receive from third parties.
Technical and behavioural tracking information for Visitors
We use cookies and similar technologies to understand interactions with our marketing emails, so that we can tailor and improve those emails. These communications are aimed at Sole Traders, Individuals in a Partnership and Merchant Representatives. You can opt out of these communications at any time to object to this processing.
Why and on what basis do we use your information?
We use the information above and other information we may collect from time-to-time for various purposes and with various legal justifications (which are called ‘lawful bases’). Our lawful bases include:
Where we need to pursue our or someone else’s legitimate interests, which does not outweigh any of your rights (Legitimate Interests).
Where we have to comply with a legal or regulatory requirement (Compliance with Law).
Where we need to process the information to perform our agreement with you (Contract Performance).
With your consent (Consent).
We rarely rely on Consent to process your information, but there are certain circumstances where we ask for your Consent for related matters. For example, under ePrivacy law, we ask for your Consent to set cookies for non-essential purposes.
We may also need to use or share the information in the section above where we consider that there is a substantial public justification for doing so, such as to protect the integrity of the payments system or prevent and detect fraudulent or other criminal activities. We may not have to inform you of this.
We only need one lawful basis to process your information, but below we outline all relevant bases.
Sole Traders, Individuals in a Partnership, Merchant Representatives and Visitors
Why we use your information?
Lawful bases
To provide you with our products and services end-to-end
To ensure that any payment transaction at your location is carried out securely
To provide you with service communications relating to our products and services
Legitimate Interests, Compliance with Law, Contract Performance
To ensure that content on our website or in our applications is presented in the most effective manner for you and for your device
Legitimate Interests, Contract Performance
To provide you with information about products and services we offer that we feel may interest you by post, telephone, SMS, email or via in-application notifications
Legitimate Interests, Consent (if relevant or an opt-out from consent under ePrivacy law)
To keep our website or our applications safe and secure
Legitimate Interests, Contract Performance
To make suggestions and recommendations to you and other users of our website and our applications about goods or services that may interest you or them
Legitimate Interests
To verify your identity as well as your personal and contact information
Legitimate Interests, Compliance with Law, Contract Performance
To record and prove that payments or other transactions have been executed
Legitimate Interests, Compliance with Law, Contract Performance
To initiate, exercise and defend any legal claim or collection procedure
Legitimate Interests, Compliance with Law, Contract Performance
To conduct compliance procedures
Legitimate Interests, Contract Performance
Legitimate Interests
To analyse customer data and understand our customer base to inform and refine our marketing, advertising and general business strategy.
Legitimate Interests
To improve our customer service and other internal capabilities and enhance your customer experience
Legitimate Interests
To conduct internal investigations in relation to fraud and security matters
Legitimate Interests
To share your information with product partners, such as Capital on Tap, to assess your eligibility for and set or review any limits for products offered under our brand.
Consent, Legitimate Interests
Consumers
Why we use your information?
Lawful bases
To process a payment made by you via our products and services using your card or any other means of payment available from time to time.
Legitimate Interests, Compliance with Law
To ensure that any payment transaction you make is carried out in a secure manner and mitigate the risk of fraud or any other criminal activity (including any related investigations).
Legitimate Interests, Compliance with Laws
To provide you with a receipt
Legitimate Interests
Aggregated/Anonymised Datasets
In connection with our analysis of certain data sets (including consumer spending and related transaction behaviour), we may, from time to time, use personal data to create aggregated and/or anonymised datasets which we may use for our own purposes or make available to third parties.
Which third parties may we share your information with?
We may also share your information with the following third parties.
Companies in our corporate group
C T Bikes Limited so we may share your information within our group in ordinary course of business.If you receive services in Ireland or another EEA signatory state,
Suppliers and subcontractors
– Logistics providers, which support us in the fulfilment of the provision and return of hardware.
– Customer support providers, who support us in supporting our merchants in relation to our products and services.
Fraud prevention agencies
When applying for any of our payments services, we undertake checks for the purposes of preventing fraud and money laundering and identity verification. Where we do so, we may share certain of the information listed in section 4 with fraud prevention agencies.
We and fraud prevention agencies may also enable law enforcement agencies to access and use your information to detect, investigate and prevent crime. We provide context on our lawful bases in section 5.
Fraud prevention agencies can hold your information for different periods of time, and if you are considered to pose a fraud or money laundering risk, your information can be held for up to six years (or longer, subject to local law) by a fraud prevention agency. For information on how we calculate our own retention periods, see section 6.
If we, or a fraud prevention agency, determine that you pose a fraud or money laundering risk, we may refuse to provide the services or financing you have requested, or to employ you, or we may stop providing existing services to you.
A record of any fraud or money laundering risk will be retained by the fraud prevention agencies, and may result in others refusing to provide services, financing or employment to you.
You can contact fraud prevention agencies directly. Any use of your information independently by a fraud prevention agency is subject to the relevant agency’s privacy policy. In the UK, please seeCIFAS: http://cifas.org.uk/fpn
If you are based in an EEA signatory state, the relevant processing will be carried out by an equivalent or similar fraud prevention agency, which you can contact directly. Please contact us if you would like us to direct you to the relevant agency’s notice.
User experience, service design and market research agencies
We partner with user experience, service design and market research agencies which assist us with the improvement and optimisation of our products and services, along with other market research projects.
What are my rights and how can I raise a complaint?
You have several rights under data protection laws. Some of these rights are subject to exceptions. You can exercise your rights through the details above.
Right to be informed
You have a right to be told about how and why we process your information. We do that through this Privacy Policy and other information we may make available.
Right to access
You have a right to access that information we hold on you. This right does not extend to accessing information on other people or businesses.
Right to deletion
You have a right to have information about you deleted or erased, unless an exception applies. In some cases, we need to retain information due to legal or regulatory requirements. This is also known as the ‘right to be forgotten’.
Right to restrict
You have a right to restrict how we use your information in certain circumstances, such as where you think it is inaccurate.
Right to portability
You have a right to receive your information in a structured, commonly-used and machine-readable format or have it shared with another data controller if we process your information based on Consent or Contract Performance.
Right to object
You have a right to object to the processing of your information based on Legitimate Interests, except where we have ‘compelling interests’ which override that. An example would be where we consider the processing necessary to ensure the safety of the financial services sector.
Right to withdraw your consent
You have a right to withdraw your Consent at any time if we rely on this as our legal basis. If you do this, we will stop further processing the relevant information on that basis, but may rely on another basis.
We do not routinely rely on Consent for any processing activity, except where we need to under ePrivacy law (in relation to cookies and certain electronic marketing activities).
R
You also have the right to raise a complaint with us or the relevant supervisory authority, as outlined in Section 2 above.
To help us investigate your complaint, please provide:
Your name, contact details, and merchant identification (if you have one).
Full details of your complaint.
If you are submitting a complaint on someone’s behalf, we will ask you to provide proof of authority to act on that person’s behalf. In some cases we may also ask you to provide proof of identity if we are unable to verify your identity from our existing records.
If you are based in the UK, we will acknowledge your complaint within 30 days. We aim to resolve all complaints without undue delay.
Security
We have in place a level of security appropriate to the nature of the information we process and the harm that might result from a breach of security. Your information is stored on our secure servers. The transmission of any payment transactions will be encrypted using TLS technology.
All environments that are used in the processing, storage or transmission of payment card details are PCI DSS compliant and, as a Level 1 Service Provider, our compliance is assessed by an independent Qualified Security Assessor (QSA) on an annual basis.
Controllers and processors
If a third party processes your information on our instruction they are likely to be a data processor. An example of this will be in relation to our suppliers of IT and marketing services. In such cases, we only share your information for purposes that are compatible with the reasons contained in this Privacy Policy. All data processors are subject to written agreements that ensure we retain control over how that information is used.
If a third party is considered to be a data controller, we are not able to dictate how that third party will process the data that has been provided. Examples of common third party data controllers are credit rating agencies and financial institutions. In such cases, the data protection policies of the third party data controller will apply.
14. Glossary
AML means anti-money laundering.
CTF means counter-terrorism financing.
Data controller means a person who determines how and why personal data is processed.
Data processor means a person who processes personal data on behalf of a data controller.
EEA means the European Economic Area.
ePrivacy law means the law relating to electronic communications, including the use of cookies and similar technologies and the sending of email marketing messages.
KYB means know-your-business.
KYC means know-your-customer.
PC means a Dojo payment consultant who supports us in selling our payment services.
Personal data means any information relating to an identified or identifiable individual.
UK means United Kingdom.




