Data Processing Agreement

Last updated June 16, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between PayTo.us ("Processor") and any Merchant ("Controller") that uses the Platform to collect or process personal data of its Buyers. It describes how PayTo.us processes that personal data on the Controller's behalf and reflects the requirements of applicable data-protection law, including the GDPR where it applies.

1. Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Supervisory Authority" have the meanings given in applicable data-protection law. "Buyer Data" means personal data of a Merchant's customers processed through the Platform.

2. Roles and Scope

With respect to Buyer Data, the Merchant is the Controller and PayTo.us is the Processor. PayTo.us processes Buyer Data only to provide the Platform and only on the documented instructions of the Controller, including as set out in our Terms and this DPA.

3. Details of Processing

4. Processor Obligations

5. Sub-processors

The Controller authorizes PayTo.us to engage sub-processors to support the service, including our Payment Processor (Stripe) and our hosting and infrastructure providers. We impose data-protection obligations on sub-processors that are no less protective than those in this DPA, and we remain responsible for their performance.

6. Security Measures

We maintain measures designed to protect Buyer Data, including encryption in transit, access controls and authentication, network protections, logging, and reliance on a PCI-DSS-compliant Payment Processor for cardholder data.

7. Data Subject Requests

Where a Data Subject contacts PayTo.us to exercise their rights regarding Buyer Data, we will, where legally permitted, refer the request to the relevant Controller and reasonably assist the Controller in responding.

8. Personal Data Breach

PayTo.us will notify the affected Controller without undue delay after becoming aware of a personal-data breach affecting Buyer Data and will provide information reasonably available to assist the Controller in meeting its notification obligations.

9. International Transfers

Where Buyer Data is transferred across borders, such transfers are made subject to appropriate safeguards, such as Standard Contractual Clauses or another lawful transfer mechanism.

10. Audit

Upon reasonable written request, PayTo.us will make available information necessary to demonstrate compliance with this DPA, which may take the form of third-party certifications or reports where available.

11. Return and Deletion

On termination of the service, PayTo.us will delete or return Buyer Data in accordance with the Controller's instructions, except where retention is required by law.

12. Contact

For matters relating to this DPA, contact our data protection team through our contact form or email dpo@payto.us.