Compliance
Last updated: March 2026
1. Regulatory Framework
Filoosy Information Technology (CR No. 111367-08) operates as a licensed e-payment gateway and payment service provider under the regulatory oversight of the Central Bank of Bahrain (CBB). We are fully committed to complying with all applicable laws, regulations, and industry standards governing payment services in the Kingdom of Bahrain and the GCC region.
2. PCI DSS Compliance
Filoosy maintains compliance with the Payment Card Industry Data Security Standard (PCI DSS), the global security standard for all organizations that handle cardholder data. Our PCI DSS compliance includes:
- Secure network architecture with firewalls and encryption
- Protection of stored cardholder data through tokenization
- Strong access control measures and unique user identification
- Regular security testing and vulnerability assessments
- Comprehensive information security policy maintained and updated regularly
3. Anti-Money Laundering (AML)
Filoosy maintains a robust AML programme in accordance with the CBB's regulatory requirements and international best practices. Our AML measures include:
- Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) procedures
- Know Your Customer (KYC) verification for all merchants
- Transaction monitoring systems to detect suspicious activity
- Suspicious Activity Report (SAR) filing procedures
- Regular AML training for all staff members
- Designated AML Compliance Officer
4. Counter-Terrorist Financing (CTF)
In line with Bahraini law and CBB directives, Filoosy implements strict measures to prevent the use of our payment services for terrorist financing. We screen all merchants and transactions against international sanctions lists and maintain procedures for reporting any suspected terrorist financing activity to the relevant authorities.
5. Data Protection
Filoosy complies with Bahrain's Personal Data Protection Law (PDPL) and implements comprehensive data protection measures:
- Data minimization — we only collect data necessary for our services
- Purpose limitation — data is used only for stated purposes
- Encryption of personal data in transit and at rest
- Data retention policies aligned with regulatory requirements
- Data breach notification procedures
- Regular privacy impact assessments
6. Card Network Compliance
Filoosy maintains compliance with the operating regulations of all major card networks we support, including Visa, Mastercard, American Express, MADA, and Benefit. We adhere to their rules governing transaction processing, dispute resolution, data security, and merchant monitoring.
7. Fraud Prevention
Our fraud prevention framework includes:
- Real-time transaction monitoring with machine learning algorithms
- 3D Secure authentication for online card payments
- Velocity checks and anomaly detection
- Device fingerprinting and geolocation verification
- Manual review processes for flagged transactions
8. Business Continuity
Filoosy maintains a comprehensive Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) to ensure uninterrupted payment processing services. Our infrastructure is designed with redundancy and failover capabilities to maintain our commitment to 99.99% uptime.
9. Audit and Reporting
Filoosy undergoes regular internal and external audits to verify our compliance with all applicable standards and regulations. We submit required regulatory reports to the CBB and other relevant authorities as mandated. Audit findings are reviewed by senior management and addressed promptly.
10. Contact Our Compliance Team
For compliance-related inquiries, please contact us:
Filoosy Information Technology
Office 61, Building 371, Road 1912, Block 319
Al Hoora, Kingdom of Bahrain, PO Box 54444
Email: info@filoosy.net
Phone: +973 17827278