Ogloba operates a payment-adjacent platform serving enterprise retail brands across more than 60 countries. This page summarises our compliance posture and the controls we operate to protect customers, partners, and end consumers.
1. Regulatory frameworks
Ogloba designs its platform to support customer compliance with the laws applicable to gift card, prepaid, and loyalty programs in each market — including PSD2 (EU), PCI-DSS where card data is processed, GDPR, UK Data Protection Act, and local consumer-protection regimes.
2. Data protection & privacy
We are committed to GDPR-equivalent privacy practices globally. Detailed information about how we handle personal data is in our Privacy Policy. Data-processing agreements are available on request.
3. Information security
Our platform is built and operated against an information-security management program aligned with ISO 27001 and SOC 2 control families. We perform regular penetration testing, vulnerability scanning, and third-party security reviews.
4. Anti-money-laundering & KYC
Where Ogloba acts as a processor for funds movement or stored-value programs, we follow customer-led KYC and AML rules, support transaction monitoring, and provide audit-grade logging.
5. Business continuity
Ogloba operates a documented business-continuity and disaster-recovery program with defined recovery-time objectives, regular failover testing, and geographically diverse infrastructure.
6. Trust documentation
Customers and partners under NDA can request our security questionnaire responses, sub-processor list, SOC 2 reports (where applicable), penetration-test summary, and BCP documentation.
7. Responsible disclosure
If you believe you have found a security vulnerability in Ogloba services, please email security@ogloba.com. We acknowledge reports within two business days and credit reporters who follow our coordinated-disclosure process.