BrightBooks Payment Manager is built to comply with GDPR and applicable data protection legislation. This article explains who is responsible for your data, what security standards apply, and how your clients' payment information is handled.
Security standards
| Standard | What it means |
| PCI DSS Level 1 certified | The highest certification level for handling card payment data — ensures your clients' card details are fully protected. |
| 3D Secure (3DS) / PSD2 compliant | Strong Customer Authentication (SCA) is applied to card transactions, in line with PSD2 requirements. |
| SOC 2 Type II certified | Unipaas holds an independently audited SOC 2 Type II certificate covering the security, confidentiality, and availability of systems used to process and protect your data. |
| FCA regulated | Unipaas Financial Services Ltd is an FCA‑authorised payment institution (licence 929994). |
| KYC / KYB / AML checks | Automated Know Your Customer, Know Your Business, and Anti‑Money Laundering checks are run during account onboarding. |
Who is the data controller?
The data controller is:
The registered address applicable to your account will be confirmed in your service agreement. Contact BrightBooks support if you require specific data controller details for your region.
Unipaas Europe Limited, acting as a data processor under the terms of the payment services agreement.
Is Payment Manager GDPR compliant?
Yes. Payment Manager is built to comply with GDPR and all applicable data protection legislation. Personal and payment data is processed only for the purposes of providing the payment service. Appropriate technical and organisational safeguards are in place.
Does my client need to consent when they pay?
When a client clicks Pay Now, they are taken to a secure Unipaas‑hosted payment page where they enter their payment details. Clients are presented with the necessary terms and privacy information at that point.
Bright does not store your clients' full card details. Only Unipaas, as an approved and regulated data processor, holds that data.
What happens to my data if I stop using Payment Manager?
If you close your Payment Manager account, your transaction history remains accessible in BrightBooks for record‑keeping purposes in line with standard data retention requirements and applicable law. No further payments can be processed once the account is closed.
For specific questions about data retention or deletion, contact BrightBooks support at brightbookssupport@brightsg.com.