This Data Processing Agreement ("DPA") forms part of the agreement between PayTo.us ("Processor") and any Merchant ("Controller") that uses the Platform to collect or process personal data of its Buyers. It describes how PayTo.us processes that personal data on the Controller's behalf and reflects the requirements of applicable data-protection law, including the GDPR where it applies.
1. Definitions
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Supervisory Authority" have the meanings given in applicable data-protection law. "Buyer Data" means personal data of a Merchant's customers processed through the Platform.
2. Roles and Scope
With respect to Buyer Data, the Merchant is the Controller and PayTo.us is the Processor. PayTo.us processes Buyer Data only to provide the Platform and only on the documented instructions of the Controller, including as set out in our Terms and this DPA.
3. Details of Processing
- Subject matter: provision of payment-facilitation and related services.
- Duration: for the term of the Merchant's use of the Platform and any legally required retention period.
- Nature and purpose: collecting payments, managing orders and subscriptions, issuing refunds, and preventing fraud.
- Types of data: name, email, billing details, transaction records, and technical identifiers such as IP address.
- Data subjects: the Merchant's Buyers and customers.
4. Processor Obligations
- Process Buyer Data only on the Controller's documented instructions;
- Ensure that personnel authorized to process the data are bound by confidentiality;
- Implement appropriate technical and organizational security measures;
- Assist the Controller, as reasonably practicable, in responding to Data Subject requests and meeting its compliance obligations.
5. Sub-processors
The Controller authorizes PayTo.us to engage sub-processors to support the service, including our Payment Processor (Stripe) and our hosting and infrastructure providers. We impose data-protection obligations on sub-processors that are no less protective than those in this DPA, and we remain responsible for their performance.
6. Security Measures
We maintain measures designed to protect Buyer Data, including encryption in transit, access controls and authentication, network protections, logging, and reliance on a PCI-DSS-compliant Payment Processor for cardholder data.
7. Data Subject Requests
Where a Data Subject contacts PayTo.us to exercise their rights regarding Buyer Data, we will, where legally permitted, refer the request to the relevant Controller and reasonably assist the Controller in responding.
8. Personal Data Breach
PayTo.us will notify the affected Controller without undue delay after becoming aware of a personal-data breach affecting Buyer Data and will provide information reasonably available to assist the Controller in meeting its notification obligations.
9. International Transfers
Where Buyer Data is transferred across borders, such transfers are made subject to appropriate safeguards, such as Standard Contractual Clauses or another lawful transfer mechanism.
10. Audit
Upon reasonable written request, PayTo.us will make available information necessary to demonstrate compliance with this DPA, which may take the form of third-party certifications or reports where available.
11. Return and Deletion
On termination of the service, PayTo.us will delete or return Buyer Data in accordance with the Controller's instructions, except where retention is required by law.
12. Contact
For matters relating to this DPA, contact our data protection team through our contact form or email dpo@payto.us.