This Data Processing Agreement ("DPA") forms part of the Agreement between you and 402pay under our Terms of Service, and takes effect when you accept them, without a separate signature. It applies whenever we process personal data on your behalf to provide the Services ("Customer Personal Data").
"Data Protection Laws" means the laws that apply to that processing, including the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act. Words such as controller, processor, service provider, data subject and personal data breach have the meanings those laws give them, and other capitalized terms have the meanings in the Terms of Service.
1Roles and scope
1.1Our roles
You are the controller of Customer Personal Data, or a processor acting for your own controller, and we are your processor, or your service provider under US state privacy laws. Annex 1 describes what we process, about whom and why. We are a controller of the personal data we use for our own purposes, such as your account details and the data we use to prevent fraud and meet our legal obligations, and our Privacy Notice covers that data, not this DPA.
1.2Your responsibilities
You are responsible for having a lawful basis for the processing you ask us to do, for giving your Customers the notices and getting the consents Data Protection Laws require, for the accuracy of the data you give us, and for making sure your instructions comply with those laws. Don't send us special categories of personal data, government identifiers or full card numbers, which the Services don't need.
2How we process
2.1Your instructions
We process Customer Personal Data only on your documented instructions: the Agreement, how you set up and use the Services, and any other written instructions we agree on. If the law requires other processing, we will tell you first unless the law forbids it. We will tell you if we believe an instruction breaks Data Protection Laws, and we may suspend the processing it covers until you confirm or change it.
2.2Personnel and security
Everyone we authorize to process Customer Personal Data is bound by a duty of confidentiality, trained in handling it, and given access only as their work needs. We maintain technical and organizational measures appropriate to the risk, including those in Annex 2. We may update them over time, but never in a way that lowers the overall protection of Customer Personal Data.
2.3Helping you
Taking into account what we process and the information we have, we will help you respond to requests from data subjects, meet your security obligations, carry out data protection impact assessments and consult regulators where the law requires. The Services let you find, export and delete most Customer Personal Data yourself. If a data subject contacts us directly, we will pass the request to you and not answer it ourselves unless you ask us to. Help that goes beyond what the Services provide may be at your reasonable cost.
3Sub-processors
You give us general authorization to use sub-processors to provide the Services, and we will tell you who they are on request at privacy@402pay.co. We will tell you by email or in the Dashboard at least 30 days before a new sub-processor starts processing Customer Personal Data.
You may object to a new sub-processor on reasonable data protection grounds within those 30 days. We will work with you in good faith to resolve it, and if we can't, you may end the affected Services without penalty as your sole remedy. Each sub-processor is bound in writing by data protection obligations at least as protective as this DPA, and we remain responsible for its work.
4Personal data breaches
We will tell you without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. Our notice will describe what happened, the data and people likely affected, the likely consequences and what we are doing about it, and we will add details as we learn them. We will take reasonable steps to contain the breach and help you meet your own obligations to notify regulators and data subjects. Telling you about a breach is not an admission of fault.
5Requests from authorities
If a government or other authority asks us for Customer Personal Data, we will try to redirect it to you, and we will tell you about the request unless the law forbids it. We will review each request's lawfulness, challenge it where we have reasonable grounds, and disclose only the minimum the request lawfully requires.
6International transfers
6.1From the European Economic Area
When we transfer Customer Personal Data out of the European Economic Area to a country without an adequacy decision, the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 apply and are part of this DPA: Module Two where you are a controller, and Module Three where you are a processor.
For the Clauses, Clause 7 does not apply; under Clause 9, option 2 applies with the notice period in Section 3; the optional wording in Clause 11 does not apply; under Clause 13, the supervisory authority is the one for where you are established; and under Clauses 17 and 18, the law and courts of Ireland apply. Annex I of the Clauses is Annex 1 of this DPA, and Annex II is Annex 2.
6.2From the United Kingdom and Switzerland
When we transfer Customer Personal Data out of the United Kingdom to a country without adequacy regulations, the International Data Transfer Addendum to the Standard Contractual Clauses, issued by the Information Commissioner, applies and is part of this DPA. Its Table 1 takes the parties' details from the Agreement, Table 2 selects the modules and options in Section 6.1, Table 3 is completed by Annex 1 and Annex 2, and under Table 4 neither party may end the Addendum under its Section 19.
For transfers from Switzerland, the Standard Contractual Clauses apply as in Section 6.1, with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner as a competent supervisory authority.
6.3If a mechanism changes
If a transfer mechanism in this section is invalidated or replaced, we will work with you in good faith to adopt a lawful alternative, and the parties will sign any updated clauses the law requires.
7US state privacy laws
Where US state privacy laws apply, we will not:
- (a)sell or share Customer Personal Data, as those laws define selling and sharing;
- (b)keep, use or disclose it for any purpose other than providing the Services, or outside our direct business relationship with you;
- (c)combine it with personal data from other sources, except as those laws allow; or
- (d)try to re-identify data that has been de-identified.
We certify that we understand and will comply with these restrictions. We will give Customer Personal Data the protection those laws require of you, and tell you if we can no longer meet these commitments, in which case you may take reasonable steps to stop and fix any unauthorized use.
8Audits
We will make available the information you reasonably need to show that we meet this DPA. Once in any 12 months, or more often if a regulator requires it or after a personal data breach, you or an independent auditor bound by confidentiality may audit our compliance, with at least 30 days' notice, during business hours, without disrupting the Services and at your cost. Where independent reports or certifications cover what you want to check, we may provide those instead.
9Return and deletion
You can export Customer Personal Data from the Dashboard or the API at any time. When the Agreement ends, we will delete it within 90 days, and confirm the deletion on request, unless the law requires us to keep it. Copies in backups are deleted on their normal cycle and stay protected until then. Data recorded on public blockchains can't be deleted by anyone.
10General
This DPA lasts as long as we process Customer Personal Data. Each party's liability under it and the Standard Contractual Clauses, taken together with the Agreement, is subject to the limits in the Terms of Service, except where Data Protection Laws or the Clauses don't allow it. If this DPA and the Terms of Service conflict about Customer Personal Data, this DPA controls, and where the Clauses apply, they control over both. Apart from the Clauses, this DPA is governed by the law that governs the Agreement. Questions about it go to privacy@402pay.co.
Annex 1: Details of processing
1Subject matter, nature and purpose
We process Customer Personal Data to provide the Services: hosting checkouts and payment links, detecting and confirming payments to your wallet, showing receipts, keeping your customer records, delivering webhooks and supporting you. The processing includes collecting, storing, organizing, transmitting and deleting the data.
2Duration and frequency
The processing is continuous for as long as the Agreement lasts, and until the data is deleted under Section 9. Sub-processors process it for the same purposes and duration.
3Data subjects
- Your customers: people, and the AI agents acting for them, who pay you through the Services.
- People you add as customers in the Dashboard or through the API.
4Personal data
- Email address, name and country.
- Amounts, currencies, coins and networks paid with, and the checkout address paid to.
- The address a crypto payment was sent from and its transaction hash.
- For card payments, whether the payment was approved or why it failed.
- Notes and metadata you attach to customers and payments.
No special categories of personal data are processed. The data is processed on our cloud providers' infrastructure, which spans many countries, including the United States.
Annex 2: Security measures
1Encryption and custody
Data is encrypted in transit with TLS and at rest. A wallet's recovery phrase is encrypted in the business's own browser, with PBKDF2 and AES-GCM under a password we never receive, so we store only a copy we can't read. We never hold the keys that can spend a wallet's funds, or the funds themselves. Checkouts pay straight to addresses in the business's own wallet, normally a fresh one for each checkout.
2Access
- Sign-in uses an email address confirmed by a code, and a passkey (whose private key never leaves the user's device or password manager) or a password stored only as a salted, deliberately slow one-way hash, with limits on failed attempts, security emails and optional two-step verification.
- Every signed-in session is listed with its device and location and can be ended at any time.
- Secret API keys, recovery codes and passwords are stored only as hashes, and each key can be limited per resource.
- Staff access to personal data is limited to those who need it, protected by two-step verification and logged.
3Operations
- The Services run on a global cloud network that isolates each request and absorbs denial-of-service attacks.
- Requests that move money need an idempotency key, and every webhook delivery is signed.
- Account activity is kept in each business's audit log, and we follow a documented incident response process.
- Every provider that processes personal data for us is reviewed and bound by contract to protections at least as strong as ours.
We review these measures at least once a year.