1.1. These Terms of Use (hereinafter: the “Terms”) govern the rules of access to and use of the PayChat chatbot available on the Viber platform (hereinafter: the “Service” or “PayChat”).
1.2. The Service is developed and maintained by PayChat d.o.o., Belgrade, company registration number: 22097172, tax ID (PIB): 114964066 (hereinafter: “PayChat”, “we”, “us”, “our”).
1.3. By using the Service, the User confirms that they have read, understood and accepted these Terms. If the User does not agree with the Terms, they should not use the Service.
1.4. Key note on the nature of the Service: PayChat is a communication and technical solution that enables the User, within a Viber conversation, to create, receive, forward and manage payment requests and to prepare data for initiating payments.
1.5. PayChat is not a payment institution and does not provide payment services.
PayChat:
1.6. Every payment transaction is initiated, authorized and executed exclusively in the User’s mobile banking app, in accordance with the rules of that bank and of the relevant payment systems (e.g. the IPS NBS system and/or “Prenesi”), where applicable.
1.7. The Service is used via the Viber platform. The availability and functioning of the Service depend in part on the availability of Viber, the User’s internet connection and the availability of banking systems.
1.8. The “IPS NBS system” is a payment system operated by the National Bank of Serbia, used for transferring funds in dinars between participants in that system, for the purpose of executing instant credit transfers (real-time payments). “Prenesi” is a service available within the IPS NBS system that enables the transfer of funds using the recipient’s registered mobile phone number.
In these Terms, the following terms have the meaning:
2.1. User – a natural or legal person who uses the Service via their Viber account and the corresponding phone number.
2.2. Request Sender – the User who creates and sends a Payment Request.
2.3. Request Recipient – the User to whom a Payment Request is addressed.
2.4. Payment Request – a message/data structure generated in PayChat by which the Recipient is asked to pay a specified amount, together with a description and other data relevant for initiating the payment.
2.5. Payment Transaction – a payment that the User initiates, authorizes and executes exclusively in the mobile banking app, after that app accepts the Payment Request created via the PayChat service and forwarded in the form of a deeplink. The Payment Transaction is executed by the bank. PayChat enables solely the creation and forwarding of the Payment Request to the mobile banking app.
2.6. Payment Data – informational data related to a Payment Request (e.g. amount, description, phone number, request identifier, request status), without data considered a banking secret.
2.7. Deeplink – a technical feature that redirects the User from the Viber conversation into the mobile banking app for the purpose of reviewing, authorizing and executing a transaction.
2.8. User’s Bank – the bank at which the User holds an account and whose mobile banking app the User uses to authorize and execute payments.
3.1. PayChat enables the User, within a Viber conversation, to:
3.2. PayChat cannot guarantee that every action in the Service will result in a successful payment, because:
3.3. PayChat does not require the User to create a separate PayChat account. Use of the Service is tied to the User’s Viber account and phone number.
3.4. A precondition for executing a payment is that the User has a mobile banking app and that the bank supports the relevant method of execution (e.g. the IPS NBS system and/or “Prenesi”), where applicable.
3.5. The Request statuses shown in PayChat are informational and are based on the available technical information. In the event of a discrepancy, the state shown in the mobile banking app and/or the information obtained from the bank shall prevail.
3.6. PayChat may change, supplement or discontinue individual functionalities of the Service (temporarily or permanently) for the purpose of improvement, security, compliance or technological changes. Where reasonably possible, the User will be notified through communication within the Service.
4.1. The User undertakes to use the Service conscientiously, lawfully and in accordance with these Terms.
4.2. The User is responsible for the accuracy of the data they enter when creating a Request (e.g. amount, description and other data), as well as for the choice of the Request recipient.
4.3. Before each approval of a payment in the mobile banking app, the User is obliged to carefully check the transaction data (amount, recipient, description and other relevant elements) and to approve the payment only if they fully agree with the elements of the payment transaction.
4.4. Security rules (anti-phishing): The User must not share their PIN, passwords, one-time codes (OTP) or other confidential data with anyone. PayChat never requests such data.
4.5. It is prohibited to use the Service for:
4.6. If the User suspects fraud or abuse, it is recommended that they:
5.1. PayChat does not charge the User a fee for using the Service, unless expressly and clearly indicated otherwise to the User within the Service.
5.2. The User’s Bank may charge fees for executing a payment transaction, in accordance with the bank’s tariffs and terms. PayChat does not control bank fees.
6.1. PayChat provides the Service “as is” and “as available”. PayChat does not warrant that the Service will always be available without interruptions or errors.
6.2. PayChat is not liable for:
6.3. PayChat is not liable for damage arising from the User:
6.4. To the extent permitted by mandatory regulations, PayChat is not liable for indirect or consequential damage (e.g. lost profit, loss of business opportunity, reputational damage), unless such liability is mandatory by law.
6.5. PayChat’s total liability, where applicable and permitted, is limited to actual and provable damage caused solely by PayChat’s fault.
7.1. All intellectual property rights relating to the Service (software, design, trademarks, logos, databases, etc.), except for third-party elements, belong to PayChat or its licensors.
7.2. The User must not copy, modify, decompile, reverse engineer, sublicense or commercially exploit the Service without the express written consent of PayChat.
7.3. If the User provides suggestions or proposals for improvement, PayChat may use such feedback without restriction and without compensation, unless otherwise agreed in writing.
8.1. PayChat processes only the data necessary for the functioning of the Service: the phone number and display name of the User in the Viber environment, the User’s technical identifier, Request data (recipient’s phone number, amount, description, identifier, status, selected bank) and technical records. The display name is set by the User and need not correspond to their real name; PayChat does not verify the User’s identity.
8.2. PayChat does not collect or store banking secrets such as account numbers, PIN, passwords, one-time codes (OTP), account balance data or the final execution status of a transaction.
8.3. PayChat keeps records of Requests and their statuses within the Service. A Request becomes a Payment Transaction only if the User authorizes and executes it in the mobile banking app; at the moment a Request is created and sent, PayChat cannot know whether the Request will be realized. For Payment Transaction data, the User’s Bank is an independent (separate) controller; PayChat has no control over the processing of data in the bank’s systems.
8.4. Forwarding data to the bank (deeplink): in order to initiate a payment in the mobile banking app, PayChat prepares a deeplink containing the recipient’s phone number, amount, message/purpose, Request identifier and the identifier of the selected bank. This data is transferred to the mobile banking app of the selected bank exclusively by the User’s activation of the deeplink, locally on their device; PayChat does not deliver it to the bank via a server. By accepting these Terms and activating the deeplink, the User is informed and agrees that the said data is transferred to the selected bank in that manner.
8.5. Details on data processing, recipients, retention periods and the rights of data subjects are governed by PayChat’s Privacy Policy, which is set out in Annex 1 to these Terms, forms an integral part thereof and is also available at www.paychat.rs. By accepting these Terms, the User confirms that they are also familiar with the Privacy Policy.
9.1. The User may stop using the Service at any time by ceasing communication with the bot and/or removing/blocking the bot on the Viber platform.
9.2. PayChat may temporarily restrict or suspend access to the Service, without prior notice, when reasonably necessary in order to:
9.3. PayChat may permanently block a User in the event of a serious or repeated breach of the Terms, in particular in connection with prohibited activities.
9.4. Upon termination of use or blocking, the User loses access to the functionalities of the Service. Provisions that by their nature should remain in force (e.g. intellectual property, limitation of liability, dispute resolution) shall remain in force after termination.
10.1. The User may submit a complaint or a support request via the Contact form at www.paychat.rs and/or via the e-mail address: support@paychat.rs.
10.2. Complaints regarding the PayChat Service cover matters such as technical difficulties in creating/sending/receiving Requests, display of Request status, deeplink problems, blocking of users and the like. PayChat will endeavor to respond within 8 days at the latest, and in more complex cases within 15 days at the latest, with notice of the progress of resolution.
10.3. Complaints regarding the execution of a transaction (approval/rejection, delay, fees, limits, refunds, cancellation and complaints about an executed payment) are resolved with the User’s Bank, since the transaction is initiated, authorized and executed exclusively in the mobile banking app.
10.4. For a complaint to be handled efficiently, the User should state the date and time of the event, the phone number associated with the Viber account, a description of the problem and, where possible, the Request/transaction identifier and a screenshot.
11.1. These Terms are interpreted and applied in accordance with the substantive and procedural law of the Republic of Serbia.
11.2. Complaints regarding the execution of payment transactions are resolved by the User with their bank, in accordance with the framework agreement and the regulations governing payment services and the protection of financial-services users.
11.3. Disputes and complaints relating to the functioning of the PayChat Service are resolved through PayChat support.
11.4. The parties will endeavor to resolve any dispute amicably. If the dispute is not resolved amicably, the court with subject-matter jurisdiction in Belgrade shall have jurisdiction, unless mandatory regulations provide otherwise.
12.1. Support contact: support@paychat.rs.
12.2. The User accepts that communication and notices relating to the Service may be made electronically: through the Viber conversation with the bot, through notifications within the Service and/or via the stated support e-mail address.
13.1. Force majeure: PayChat is not liable for non-performance or delay due to events beyond its reasonable control (e.g. internet outages, failures of third-party systems, changes to the Viber platform, failures of banking systems, force majeure).
13.2. Partial invalidity: If any provision of these Terms is null or unenforceable, the remaining provisions shall remain in force.
13.3. Transfer of rights and obligations: PayChat may transfer its rights and obligations to an affiliated entity or legal successor, upon notice to the User, provided that this does not diminish the User’s statutory rights.
13.4. Amendments to the Terms: PayChat may amend these Terms. The User will be notified of amendments through the Service. Continued use of the Service after the amendments take effect is deemed acceptance of the amendments.
13.5. Entry into force: These Terms enter into force on the date of publication and apply from that date to all Users.
(This Policy is aligned with the Personal Data Protection Act, “Official Gazette of RS” No. 87/2018.)
P1.1. The controller of personal data within the meaning of the Personal Data Protection Act (“Official Gazette of RS”, No. 87/2018, hereinafter: the “Act”) is PayChat d.o.o., Belgrade, company registration number: 22097172, tax ID (PIB): 114964066 (hereinafter: “PayChat”, “we”).
P1.2. Contact for all questions and the exercise of rights relating to personal data protection: support@paychat.rs, as well as via the contact form at www.paychat.rs. Given the scope and nature of the processing, PayChat is not obliged to designate a data protection officer within the meaning of Article 56 of the Act, but the stated contact is the single point of contact for all processing matters.
P1.3. This Privacy Policy (hereinafter: the “Policy”) forms an integral part of the Terms of Use of the PayChat service and applies to the processing of personal data within the Service.
The terms User, Request Sender, Request Recipient, Payment Request (Request), Payment Transaction (Transaction), Payment Data, Deeplink and User’s Bank have the meaning established in Section 2 of the Terms of Use. In addition, in this Policy:
P3.1. PayChat is a communication-intermediary service and is not a payment service provider; it does not execute payment transactions, does not hold User funds, does not initiate or authorize payments, and does not collect or store sensitive banking data (PIN, passwords, one-time codes/OTP).
P3.2. For the data contained in a Request, PayChat is the controller. For Transaction data, the User’s Bank is an independent controller, in accordance with its general terms and the regulations governing payment services and banking secrecy. PayChat keeps records of Requests and their statuses within the Service, but does not and cannot know whether an individual Request will ever be realized as a Transaction, nor does it have the execution status of an individual Transaction. The statuses shown in the Service are informational; only the state in the mobile banking app is authoritative.
PayChat processes personal data in accordance with the principles of Article 5 of the Act: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality. The principle of minimization is built into the very architecture of the Service: due to its limited intermediary role, PayChat processes a significantly narrower set of data than executing financial systems.
P5.1. User data:
P5.2. Request data: the Recipient’s phone number; amount; message/description (purpose) entered by the User; the Request identifier and the Request status within the Service (e.g. created, sent, accepted, rejected, expired); the choice of bank to which the User wishes to be directed.
P5.3. Technical data: technical records (logs) on the functioning of the Service, to the extent necessary for security, error remediation and abuse prevention.
P5.4. Data that PayChat does NOT process: User’s or Recipients’ payment account numbers; PIN, passwords, one-time codes (OTP) and other bank authentication data; data on account balance, limits or other banking products; the final execution status of a Transaction; any other data constituting a banking secret within the meaning of the Banking Act, which is created or processed in the bank’s information systems.
P6.1. When creating a Request, i.e. when confirming a payment to a third party, the Sender selects from their contact list and shares with PayChat the Recipient’s phone number, in order to form the Request and the corresponding deeplink. In doing so, PayChat processes the phone number of a person from whom that data was not directly collected, within the meaning of Article 24 of the Act.
P6.2. Processing is limited to the minimum: the phone number is used exclusively to form the Request and the corresponding deeplink.
P6.3. Notification of the Recipient: if the Recipient is a user of the Service, they receive the processing information under Article 24 of the Act through the Service itself — by receiving the Request in the Viber conversation with the Service, together with the availability of this Policy. If the Recipient is not a user of the Service, PayChat does not contact them nor, given the nature of the chatbot channel on the Viber platform, can it technically send them a message, and their phone number is used exclusively to prepare data that the Sender themselves transfers to their bank by activating the deeplink; individual notification of such persons would be impossible or would require disproportionate effort within the meaning of Article 24, paragraph 5 of the Act, so the processing information is provided by publishing this Policy at www.paychat.rs.
P6.4. The Sender is responsible for the accuracy of the Recipient data they enter and warrants that they use third-party data conscientiously and lawfully.
P7.1. PayChat processes personal data for the following purposes and on the following legal bases:
P7.2. PayChat does not use personal data for marketing nor does it sell personal data to third parties. If PayChat were in the future to intend to process data for a purpose other than the purpose for which it was collected, before commencing such processing it will provide the User with information about that other purpose.
P8.1. The following entities have access to the data processed within the Service, each in a clearly defined role:
P8.2. No one else has access to the data. PayChat does not provide Request data to banks, Viber or any third party on its own initiative, via a server or otherwise, except as described in this Privacy Policy.
P9.1. When the User decides to proceed to payment, PayChat generates a deeplink containing the following set of data: the Recipient’s phone number; amount; payment message/purpose; Request identifier; identifier of the selected bank.
P9.2. Method of transfer: the deeplink is activated exclusively by an action of the User (tapping a button/link) and is executed locally on the User’s device — the device’s operating system forwards the deeplink parameters to the mobile banking app. PayChat does not send this data to the bank via a server or to any third party; the data is transferred to the bank by the User themselves, by their own action, as the person initiating the payment.
P9.3. The data contained in the deeplink is simultaneously displayed to the User in the Request summary within the Viber conversation, before the deeplink is activated, so that the User is at all times aware of which data is being prepared for initiating the payment and to which bank it is being directed.
P9.4. From the moment the mobile banking app is opened, all further processing of data (authentication, display, authorization, execution, transaction recording) is carried out exclusively by the bank as an independent controller, in accordance with its terms and the regulations on banking secrecy. PayChat has no insight into these processes or their outcome.
P10.1. Request data (including statuses) is kept for a maximum of 3 (three) years from the creation of the Request, whereby PayChat reserves the right to keep it for a shorter period; after the retention period expires, the data is deleted or irreversibly anonymized.
P10.2. Technical logs are kept for a maximum of 12 (twelve) months from creation, whereby PayChat reserves the right to keep them for a shorter period, unless longer retention is necessary for a specific security incident, complaint or legal obligation.
P10.3. Data relating to complaints is kept until the complaint procedure is concluded and the periods within which legal proceedings may be initiated expire. After the retention periods expire, the data is securely deleted or anonymized.
P11.1. Every person whose data PayChat processes has, in accordance with the Act, the right to: access to data and information on processing (Article 26); rectification and supplementation (Article 29); erasure (Article 30); restriction of processing (Article 31); data portability (Article 36); objection to processing based on legitimate interest (Article 37); withdrawal of consent, where processing is based on consent, without affecting the permissibility of processing prior to withdrawal.
P11.2. Requests are submitted to support@paychat.rs. PayChat responds without delay, and no later than 30 days from receipt of the request; that period may be extended by a further 60 days if necessary given the complexity and number of requests, of which the person will be notified within 30 days from receipt of the request. Handling requests is free of charge, except in the case of manifestly unfounded or excessive requests.
P11.3. A person has the right to lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, 11120 Belgrade, tel: +381 11 3408 900, e-mail: office@poverenik.rs, www.poverenik.rs.
P11.4. Note: requests relating to Transaction data (execution, amounts, statuses, accounts) are submitted to the User’s Bank, since PayChat does not hold that data.
P12.1. PayChat does not carry out profiling or automated decision-making that produces legal effects concerning the User or significantly affects them within the meaning of Article 38 of the Act. The automated functions of the Service are limited to the technical management of the user flow (displaying options, recording statuses, generating deeplinks) and do not include the assessment of the User’s personal characteristics.
P13.1. PayChat does not collect or process special categories of personal data under Article 17 of the Act (data on racial or ethnic origin, political opinion, religious or philosophical belief, trade union membership, genetic and biometric data, data on health, sex life or sexual orientation).
P14.1. PayChat applies technical and organizational protection measures proportionate to the risks of processing, including: encryption of data in transit, control and restriction of access on a least-privilege basis, access logging and regular backups. The PayChat administrative platform is accessed exclusively by authorized employees, applying all security measures and mandatory two-factor authentication (2FA).
P14.2. PayChat never requests from the User a PIN, passwords, one-time codes or other confidential banking data. Any such request constitutes an attempted fraud and should be reported to the bank and PayChat support.
P15.1. The data controlled by PayChat is processed on servers in the Republic of Serbia (Comtrade Cloud, data centar in Belgrade). PayChat does not transfer personal data to other countries or international organizations.
P15.2. The Viber platform, as an independent controller, may process data on servers outside the Republic of Serbia, in accordance with its own privacy policy. PayChat has no control over that processing.
P16.1. The Service is intended for persons who meet the requirements for using a mobile banking app.
P17.1. PayChat may amend this Policy. The current version is always available at www.paychat.rs, and the User will be notified of material amendments through the Service. Amendments to the Policy are made in the manner provided for amendments to the Terms of Use (Section 13.4 of the Terms).