Privacy Policy
Last updated: January 2026
Overview
Peppa provides enterprise software middleware to licensed financial institutions. This policy describes how Peppa handles information as a data processor operating strictly on behalf of its partner institutions.
Information we process
Peppa processes limited operational data required to orchestrate payment and value flows, including transaction metadata, integration identifiers, and audit logs. All personal financial data remains within the regulatory perimeter of the partner institution.
How we use information
We use information only to operate, maintain, and improve the middleware services requested by our partners, and to meet contractual obligations documented in each partner agreement.
Security
Peppa applies industry-standard security controls, including encryption in transit and at rest, role-based access, audit logging, and least-privilege operational practices.
Contact
Questions about this policy can be sent to privacy@peppa.io.