1.1. These Terms of Use (hereinafter: the „Terms“) govern the rules for accessing and using the PayChat chatbot available on the Viber platform (hereinafter: the „Service“ or „PayChat“).
1.2. The Service is developed and maintained by PayChat d.o.o., Belgrade, company registration number: 22097172, tax ID (PIB): 114964066 (hereinafter: “PayChat”, “we”, “us”, “our”).
1.3. By using the Service, the User confirms that they have read, understood, and accepted these Terms. If the User does not agree with the Terms, they should not use the Service.
1.4. Key note on the nature of the Service: PayChat is a communication and technical solution that enables the User, within a Viber conversation, to create, receive, forward, and manage payment requests and to prepare data for initiating payments.
1.5. PayChat is not a payment service provider and does not provide payment services within the meaning of the Law on Payment Services („Official Gazette of RS“, Nos. 139/2014, 44/2018 and 64/2024).
PayChat:
1.6. Every payment transaction is initiated, authorized, and executed exclusively in the User’s mobile banking app, in accordance with the rules of that bank and the relevant payment systems (e.g. the IPS NBS system and/or „Prenesi“), where applicable.
1.7. The Service is used via the Viber platform. The availability and functioning of the Service depend in part on the availability of Viber, the User’s internet connection, and the availability of banking systems.
1.8. The „IPS NBS system“ is a payment system operated by the National Bank of Serbia, used for transferring funds in dinars between participants in that system, for the purpose of executing instant credit transfers on a 24/7/365 basis (real-time payments).„Prenesi“ is a service available within the IPS NBS system that enables the transfer of funds using the registered mobile phone number of the payee. Banks make the „Prenesi“ service available to payment service users through their mobile banking apps.
In these Terms, the following terms have the following meanings:
2.1. User – a natural or legal person who uses the Service via their Viber account and the corresponding phone number.
2.2. Request Sender – the User who creates and sends a Payment Request.
2.3. Request Recipient – the User to whom a Payment Request is addressed.
2.4. Payment Request – a message/data structure generated in PayChat by which the Recipient is asked to make a payment of a specified amount, together with a description and other data relevant to initiating the payment.
2.5. Payment Transaction – a payment that the User initiates, authorizes, and executes exclusively in the mobile banking app, after that app accepts the Payment Request created via the PayChat service and forwarded in the form of a deeplink. The Payment Transaction is executed by the bank. PayChat enables solely the creation and forwarding of the Payment Request to the mobile banking app.
2.6. Payment Data – informational data associated with a Payment Request (e.g. amount, description, phone number, request identifier, request status), without data considered a banking secret.
2.7. Deeplink – a technical feature that redirects the User from the Viber conversation into the mobile banking app for the submission of data, authorization, and execution of the transaction.
2.8. User’s Bank – the bank at which the User holds an account and whose mobile banking app they use to initiate a payment order, give consent for the execution of the payment transaction (authorization), and execute the payment.
3.1. PayChat generates the deeplink and enables the User, within a Viber conversation, to:
Upon registering for this service, the User is acquainted with and accepts the terms of use and the privacy policy, and then selects the bank through which they will execute transactions. By clicking the deeplink, the User leaves the Viber app and the PayChat environment and moves into the mobile banking app. Only a user (request sender) who is registered for use of the „Prenesi“ service with the bank at which they hold a payment account can receive funds.
3.2. PayChat cannot guarantee that every action within the Service will result in a successful payment, because:
3.3. PayChat does not require the User to create a separate PayChat account. Use of the Service is tied to the User’s Viber account and phone number.
3.4. A precondition for executing a payment is that the User has a mobile banking app and that the bank supports the relevant method of execution (e.g. the IPS NBS system and/or “Prenesi”), where applicable.
3.5. The statuses of Requests shown in PayChat are informational and are based on the available technical information. In the event of a discrepancy, the state shown in the mobile banking app and/or information obtained from the bank shall prevail.
3.6. PayChat may modify, supplement, or discontinue individual functionalities of the Service (temporarily or permanently) for the purposes of improvement, security, compliance, or technological changes. Where reasonably possible, the User will be notified through communication within the Service.
4.1. The User undertakes to use the Service conscientiously, lawfully, and in accordance with these Terms.
4.2. The User is responsible for the accuracy of the data they enter when creating a Request (the choice of the Request’s recipient, the amount, and the optional message accompanying the request).
4.3. Before each approval of a payment in the mobile banking app, the User is obliged to carefully verify the transaction data (amount, recipient, description, and other relevant elements) and to approve the payment only if they fully agree with the elements of the payment transaction.
4.4. Security rules (anti-phishing): The User must not share their PIN, passwords, one-time passcodes (OTP), or other confidential data with anyone. PayChat never requests such data.
4.5. It is prohibited to use the Service for:
4.6. If the User suspects fraud or abuse, it is recommended that they:
5.1. PayChat does not charge the User a fee for using the Service, unless expressly and clearly indicated otherwise to the User within the Service.
5.2. The User’s Bank may charge fees for executing a payment transaction, in accordance with the bank’s tariffs and terms. PayChat does not control banking fees.
6.1. PayChat provides the Service „as is“ and „as available“, i.e. PayChat gives no warranty that the Service will always be available without interruptions or errors.
6.2. PayChat is not liable for:
6.3. PayChat bears no liability for damage arising from the User:
6.4. To the maximum extent permitted by the mandatory regulations of the Republic of Serbia, PayChat is not liable for indirect, consequential, incidental, or non-material damage, including lost profit, loss of revenue, loss of business opportunity or contract, loss, corruption, or unavailability of data, loss of anticipated savings, reputational harm, and the costs of procuring a replacement service, regardless of the legal basis of liability and regardless of whether PayChat was advised of the possibility of such damage occurring. This exclusion does not apply to damage caused intentionally or by PayChat’s gross negligence, nor in other cases in which liability is mandatory under the mandatory regulations of the Republic of Serbia.
6.5. PayChat’s total liability, where applicable and permitted, is limited to actual and provable damage caused solely by PayChat’s fault.
7.1. All intellectual property rights relating to the Service (software, design, trademarks, logos, databases, and the like), except for third-party elements, belong to PayChat or its licensors.
7.2. The User must not copy, modify, decompile, reverse engineer, sublicense, or commercially exploit the Service without PayChat’s express written consent.
7.3. If the User provides suggestions or proposals for improvement, PayChat may use such feedback without limitation and without compensation, unless otherwise agreed in writing.
8.1. PayChat processes only the data necessary for the functioning of the Service: the User’s phone number and display name in the Viber environment, the User’s technical identifier, Request data (recipient’s phone number, amount, description, identifier, status, selected bank), and technical records. The display name is determined by the User and need not correspond to their real name; PayChat does not verify the User’s identity.
8.2. PayChat does not collect or store banking secrets such as account numbers, PIN, passwords, one-time passcodes (OTP), account balance data, or the final status of transaction execution.
8.3. PayChat keeps a record of Requests and their statuses within the Service. A Request becomes a Payment Transaction solely if the User authorizes and executes it in the mobile banking app; at the moment of creating and sending a Request, PayChat cannot know whether the Request will be realized. For data on Payment Transactions, the User’s Bank is an independent controller; PayChat has no control over the processing of data in the bank’s systems.
8.4. Forwarding data to the bank (deeplink): in order to initiate a payment in the mobile banking app, PayChat prepares a deeplink containing the recipient’s phone number, the amount, the message/purpose, the Request identifier, and the designation of the selected bank. This data is transmitted to the mobile banking app of the selected bank solely by the User’s activation of the deeplink, locally on their device; PayChat does not deliver it to the bank via server. By accepting these Terms and activating the deeplink, the User is informed of and consents to the described transmission of this data to the selected bank.
8.5. Details on data processing, recipients, retention periods, and the rights of individuals are governed by PayChat’s Privacy Policy, which is set out in Annex 1 to these Terms, forms an integral part thereof, and is also available at www.paychat.rs. By accepting these Terms, the User confirms that they are also acquainted with the Privacy Policy.
9.1. The User may cease using the Service at any time by ending communication with the bot and/or removing/blocking the bot on the Viber platform.
9.2. PayChat may temporarily restrict or suspend access to the Service, without prior notice, where reasonably necessary in order to:
9.3. PayChat may permanently block the User in the event of serious or repeated breach of the Terms, particularly in connection with prohibited activities.
9.4. Upon termination of use or blocking, the User loses access to the functionalities of the Service. Provisions that by their nature should remain in force (e.g. intellectual property, limitation of liability, dispute resolution) remain in force after termination as well.
10.1. The User may submit a complaint or a support request via the Contact form at www.paychat.rs and/or through the email address: support@paychat.rs.
10.2. Complaints regarding the PayChat Service cover matters such as technical difficulties in creating/sending/receiving Requests, the display of Request statuses, problems with the deeplink, blocking users, and the like. PayChat will endeavor to respond within 8 days at the latest, and in more complex cases within 15 days at the latest, with notice of the course of resolution.
10.3. Complaints regarding the execution of a transaction (approval/decline, delay, fees, limits, refund of funds, cancellation, and complaint about an executed payment) are resolved by the User with their bank, since the transaction is initiated, authorized, and executed exclusively in the mobile banking app.
10.4. For a complaint to be handled efficiently, the User should state the date and time of the event, the phone number linked to the Viber account, a description of the problem and, where possible, the identifier of the Request/transaction and a screenshot.
11.1. These Terms are interpreted and applied in accordance with the substantive and procedural law of the Republic of Serbia.
11.2. Complaints regarding the execution of payment transactions are resolved by the User with their bank, in accordance with the framework agreement and the regulations governing payment services and the protection of financial-services users.
11.3. Disputes and complaints relating to the functioning of the PayChat Service are resolved through PayChat support.
11.4. The parties will endeavor to resolve any dispute amicably. If the dispute is not resolved amicably, the court with subject-matter jurisdiction in Belgrade shall have jurisdiction, unless mandatory regulations provide otherwise.
12.1. Support contact: support@paychat.rs.
12.2. The User accepts that communication and notices relating to the Service may be made electronically: through the Viber conversation with the bot, through notices within the Service, and/or via the stated support email address.
13.1. Force majeure: PayChat is not liable for non-performance or delay due to events beyond reasonable control (e.g. internet outages, failures of third-party systems, changes to the Viber platform, failures of banking systems, force majeure).
13.2. Partial invalidity: If any provision of these Terms is null or unenforceable, the remaining provisions remain in force.
13.3. Transfer of rights and obligations: PayChat may transfer its rights and obligations to an affiliated entity or a legal successor, with notice to the User, provided that the User’s statutory guaranteed rights are not thereby diminished.
13.4. Amendments to the Terms: PayChat may amend these Terms. The User will be notified of amendments through the Service. Continued use of the Service after the amendments take effect is deemed acceptance of the amendments.
13.5. Entry into force: These Terms enter into force on the day of publication and apply from that day to all Users.
(This Policy is aligned with the Personal Data Protection Law, „Official Gazette of RS“ No. 87/2018.)
P1.1. The controller of personal data within the meaning of the Personal Data Protection Law („Official Gazette of RS“, No. 87/2018, hereinafter: the „Law“) is PayChat d.o.o., Belgrade, company registration number: 22097172, Tax ID (PIB): 114964066 (hereinafter: „PayChat“, „we“).
P1.2. Contact for all questions and the exercise of rights relating to personal data protection: support@paychat.rs, as well as via the contact form at www.paychat.rs. Given the scope and nature of the processing, PayChat is not obliged to designate a data protection officer within the meaning of Article 56 of the Law, but the stated contact is the single point for all processing matters.
P1.3. This Privacy Policy (hereinafter: the “Policy”) forms an integral part of the Terms of Use of the PayChat service and applies to the processing of personal data within the Service.
The terms User, Request Sender, Request Recipient, Payment Request (Request), Payment Transaction (Transaction), Payment Data, Deeplink, and User’s Bank have the meaning established in Section 2 of the Terms of Use. In addition, in this Policy:
P3.1. PayChat is a communication-intermediary service and is not a payment service provider; it does not execute payment transactions, does not hold User funds, does not initiate or authorize payments, and does not collect or store sensitive payment data (PIN, passwords, one-time passcodes/OTP) within the meaning of the Law on Payment Services („Official Gazette of RS“, Nos. 139/2014, 44/2018 and 64/2024).
P3.2. For data contained in a Request, PayChat is the controller. For data on a Transaction, the User’s Bank is an independent controller, in accordance with its general terms and the regulations governing payment services and banking secrecy. PayChat keeps a record of Requests and their statuses (e.g. created, sent, accepted, declined, expired) within the Service but neither knows nor can know whether an individual Request will ever be realized as a Transaction, nor does it have the execution status of an individual Transaction. The statuses shown in the Service are informational; only the state in the mobile banking app is authoritative.
PayChat processes personal data in accordance with the principles set out in Article 5 of the Law: lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality. The principle of minimization is built into the very architecture of the Service: due to its limited intermediary role, PayChat processes a substantially narrower set of data than executing financial systems.
P5.1. User data:
P5.2. Request data: the Recipient’s phone number; amount; message/description (purpose) entered by the User; the Request identifier and the Request status within the Service (e.g. created, sent, accepted, declined, expired); the choice of bank to which the User wishes to be directed.
P5.3. Technical data: technical records (logs) on the functioning of the Service, to the extent necessary for security, error remediation, and prevention of abuse.
P5.4. Data that PayChat does NOT process: payment account numbers of Users or Recipients; PIN, passwords, one-time passcodes (OTP), and other bank authentication data; data on account balance, limits, the final status of Transaction execution, and the like.
P6.1. When creating a Request, i.e. when confirming a payment to a third party, the Sender selects from their contact list and shares with PayChat the Recipient’s phone number, for the purpose of forming the Request and the corresponding deeplink. In doing so, PayChat processes the phone number of a person from whom that data was not directly collected, within the meaning of Article 24 of the Law.
P6.2. Processing is limited to a minimum: the phone number is used solely to form the Request and the corresponding deeplink.
P6.3. Notification of the Recipient: if the Recipient is a user of the Service, they receive the information on processing under Article 24 of the Law through the Service itself — upon receiving the Request in the Viber conversation with the Service, together with the availability of this Policy. If the Recipient is not a user of the Service, PayChat does not contact them nor, given the nature of the chatbot channel on the Viber platform, can it technically send them a message, and their phone number is used solely to prepare the data that the Sender themselves transmits to their bank by activating the deeplink; individual notification of such persons would be impossible or would require disproportionate effort within the meaning of Article 24, paragraph 5 of the Law, so information on processing is provided by publishing this Policy at www.paychat.rs.
P6.4. The Sender is responsible for the accuracy of the Recipient data they enter and warrants that they use third-party data conscientiously and lawfully.
P7.1. PayChat processes personal data for the following purposes and on the following legal bases:
P7.2. PayChat does not use personal data for marketing nor does it sell personal data to third parties. If PayChat were in the future to intend to process data for a purpose other than that for which they were collected, before commencing such processing it will provide the User with information on that other purpose.
P8.1. The following entities have access to the data processed within the Service, each in a clearly defined role:
P8.2. No one else has access to the data. PayChat does not disclose Request data to banks, to Viber, or to any third party on its own initiative, via server or in any other way, except as described in this Privacy Policy.
P9.1. When the User decides to proceed to payment, PayChat generates a deeplink containing the following set of data: the Recipient’s phone number; amount; the message/purpose of the payment; the Request identifier; the designation of the selected bank.
P9.2. Method of transmission: the deeplink is activated solely by the User’s action (by tapping the button/link) and is executed locally on the User’s device — the device’s operating system forwards the deeplink parameters to the mobile banking app. PayChat does not send this data to the bank via server nor to any third party; the data is transmitted to the bank by the User themselves, through their own action, as the person initiating the payment.
P9.3. The data contained in the deeplink is simultaneously shown to the User in the Request summary within the Viber conversation, before the deeplink is activated, so that the User is at all times aware of which data is being prepared for initiating the payment and to which bank it is being directed.
P9.4. From the moment the mobile banking app is opened, further processing of the data (authentication, display, authorization, execution, transaction record) is carried out exclusively by the bank as an independent controller, in accordance with its terms and the regulations on banking secrecy. PayChat has no insight into those processes or their outcome.
P10.1. Request data (including statuses) is kept for no longer than 3 (three) years from the creation of the Request, whereby PayChat reserves the right to keep it for a shorter period; after the retention period expires, the data is deleted or irreversibly anonymized.
P10.2. Technical logs are kept for no longer than 12 (twelve) months from their creation, whereby PayChat reserves the right to keep them for a shorter period, unless longer retention is necessary for a specific security incident, complaint, or legal obligation.
P10.3. Data relating to complaints is kept until the conclusion of the complaint procedure and the expiry of the periods within which legal proceedings may be initiated. After the retention periods expire, the data is securely deleted or anonymized.
P11.1. Every person whose data PayChat processes has, in accordance with the Law, the right to: access to data and information on processing (Article 26); rectification and supplementation (Article 29); erasure (Article 30); restriction of processing (Article 31); data portability (Article 36); objection to processing based on legitimate interest (Article 37); withdrawal of consent, where processing is based on consent, without affecting the permissibility of processing prior to withdrawal.
P11.2. Requests are submitted to support@paychat.rs. PayChat responds without delay, and at the latest within 30 days of receiving the request; that period may be extended by a further 60 days where necessary given the complexity and number of requests, of which the person will be notified within 30 days of receiving the request. Handling requests is free of charge, except in the case of manifestly unfounded or excessive requests.
P11.3. A person has the right to lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, 11120 Belgrade, tel: +381 11 3408 900, e-mail: office@poverenik.rs, www.poverenik.rs.
P11.4. Note: requests relating to data on Transactions (execution, amounts, statuses, accounts) are submitted to the User’s Bank, since PayChat does not hold such data.
P12.1. PayChat does not carry out profiling or automated decision-making that produces legal effects concerning the User or significantly affects them within the meaning of Article 38 of the Law. The automated functions of the Service are limited to the technical guidance of the user flow (displaying options, recording statuses, generating the deeplink) and do not include the assessment of the User’s personal characteristics.
P13.1. PayChat does not collect or process special categories of personal data under Article 17 of the Law (data on racial or ethnic origin, political opinion, religious or philosophical belief, trade-union membership, genetic and biometric data, data on health, sexual life, or sexual orientation).
P14.1. PayChat applies technical and organizational protection measures proportionate to the risks of processing, including: encryption of data in transit, control and restriction of access on the principle of least privilege, access logging, and regular backups. Only authorized employees access PayChat’s administrative platform, with the application of all security measures and mandatory two-factor authentication (2FA).
P14.2. PayChat never requests from the User a PIN, passwords, one-time passcodes, or other confidential banking data. Any such request constitutes a fraud attempt and should be reported to the bank and to PayChat support.
P15.1. Data controlled by PayChat is processed on servers in the Republic of Serbia (Comtrade Cloud, data center in Belgrade). PayChat does not transfer personal data to other countries or international organizations.
P15.2. The Viber platform, as an independent controller, may process data on servers outside the Republic of Serbia, in accordance with its own privacy policy. PayChat has no control over that processing.
P16.1. The Service is intended for persons who meet the requirements for using a mobile banking app.
P17.1. PayChat may amend this Policy. The current version is always available at www.paychat.rs, and the User will be notified of material amendments through the Service. Amendments to the Policy are made in the manner provided for amendments to the Terms of Use (Section 13.4 of the Terms).