Skip to main content

    Legal

    Data Processing Agreement

    GDPR-Compliant Addendum. This DPA forms part of the Merchant Agreement and governs the processing of Personal Data in connection with ArosaPay's transaction processing services.

    Last updated: February 2026

    1. Purpose

    This Data Processing Agreement ("DPA") governs the processing of Personal Data in connection with ArosaPay's transaction processing services. This DPA forms part of the Merchant Agreement between ArosaPay and the Merchant.

    This DPA ensures compliance with:

    • EU General Data Protection Regulation (GDPR)
    • UK GDPR (where applicable)
    • Applicable data protection laws in relevant jurisdictions

    2. Role of the Parties

    For transaction data processed under the Merchant Agreement, the following roles apply:

    • Merchant is the Data Controller — determines the purposes and means of processing Personal Data
    • ArosaPay acts as Data Processor — processes Personal Data on behalf of the Controller

    In certain limited cases, ArosaPay may act as an independent Controller as required by law, including for fraud monitoring, AML compliance, and regulatory reporting obligations.

    3. Definitions

    • "Personal Data" means any information relating to an identified or identifiable natural person
    • "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means
    • "Data Subject" means an identified or identifiable natural person whose Personal Data is processed
    • "Sub-Processor" means a third party engaged by ArosaPay to process Personal Data on behalf of the Controller

    4. Subject Matter & Duration

    Subject Matter

    Processing necessary to perform transaction processing services, including:

    • Execute payment transactions
    • Secure funds within the conditional release framework
    • Administer dispute resolution proceedings
    • Execute payout operations to merchants
    • Perform risk assessment and fraud monitoring

    Duration

    Processing continues for the term of the Merchant Agreement and any legally required retention period thereafter.

    5. Categories of Data

    ArosaPay may process the following categories of Personal Data:

    • Buyer name and merchant name
    • Phone number and email address
    • Transaction ID and payment reference
    • IP address and device metadata
    • Dispute documentation and correspondence

    ArosaPay does not process special category data (as defined under Article 9 GDPR) unless voluntarily submitted by a Data Subject in dispute documentation. Where such data is received, it is processed solely for dispute resolution purposes.

    6. Purpose of Processing

    Personal Data is processed solely for the following purposes:

    • Transaction orchestration and payment lifecycle management
    • Ledger recording and reconciliation
    • Conditional release logic and buyer confirmation workflows
    • Dispute administration and evidence review
    • Anti-money laundering (AML) monitoring
    • Fraud detection and prevention
    • Regulatory compliance and reporting obligations

    Processing is not performed for unrelated marketing, profiling, or commercial purposes unless separately consented to by the Data Subject. See the Privacy Policy for details on data handling practices.

    7. Processor Obligations

    ArosaPay shall:

    • Process Personal Data only on documented instructions from the Controller, unless required by applicable law
    • Ensure that all personnel authorized to process Personal Data are subject to confidentiality obligations
    • Implement appropriate technical and organizational security measures
    • Not sell, rent, or otherwise commercially exploit Personal Data
    • Not combine Personal Data with datasets unrelated to the services provided under the Merchant Agreement
    • Assist the Controller in responding to Data Subject requests in accordance with applicable data protection law
    • Provide reasonable assistance to the Controller in ensuring compliance with data protection impact assessments and prior consultation obligations

    8. Security Measures

    ArosaPay maintains technical and organizational security measures appropriate to the risk of processing. Full security documentation is available in the Security & Funds Safeguarding documentation.

    Measures include:

    • Encryption in transit using TLS
    • Encryption at rest for stored Personal Data
    • Role-based access control (RBAC) with least-privilege principles
    • Multi-factor authentication (MFA) for internal access to production systems
    • Audit logging of access to Personal Data
    • Immutable transaction ledger for data integrity
    • Secure key management and rotation procedures
    • Incident response procedures reviewed and tested periodically

    Security measures are reviewed periodically and updated in response to identified risks, technological developments, and regulatory guidance.

    9. Sub-Processors

    ArosaPay may engage Sub-Processors to assist in providing transaction processing services. Sub-Processors may be engaged for:

    • Cloud infrastructure hosting and data storage
    • Payment processing and payout execution via regulated PSP partners
    • Identity verification and KYC services
    • Application monitoring and security services

    Sub-Processor governance:

    • ArosaPay conducts due diligence on all Sub-Processors prior to engagement
    • Written data protection obligations equivalent to this DPA are imposed on all Sub-Processors
    • A current list of active Sub-Processors is maintained and available to the Controller upon request
    • The Controller will be notified of any intended changes to Sub-Processors, with reasonable opportunity to object

    10. International Transfers

    Where Personal Data is transferred outside the European Economic Area (EEA) or the United Kingdom, ArosaPay shall ensure that appropriate safeguards are in place:

    • Standard Contractual Clauses (SCCs) as adopted by the European Commission
    • UK International Data Transfer Agreement or UK Addendum to the EU SCCs, where applicable
    • Equivalent lawful transfer mechanisms recognized under applicable data protection law

    Transfers occur only where necessary for the provision of transaction processing services. ArosaPay will provide information regarding the transfer mechanism upon request.

    11. Data Subject Rights

    Upon request from the Controller, ArosaPay shall provide reasonable assistance in responding to Data Subject requests, including:

    • Right of access — confirmation and copy of Personal Data processed
    • Right to rectification — correction of inaccurate Personal Data
    • Right to erasure — deletion where no legal retention obligation applies
    • Right to restriction — limitation of processing in specified circumstances
    • Right to data portability — provision of Personal Data in structured, machine-readable format
    • Right to object — cessation of processing where based on legitimate interests

    Direct requests:

    Where ArosaPay receives a request directly from a Data Subject, ArosaPay shall promptly notify the Controller and shall not respond directly to the Data Subject unless legally required to do so.

    12. Data Retention

    Transaction records and associated Personal Data are retained:

    • For the duration of the contractual relationship with the Controller
    • For statutory compliance periods as required by applicable law (including tax, AML, and financial record-keeping obligations)
    • For fraud prevention analysis where proportionate and documented

    Upon termination:

    Personal Data may be deleted or anonymized in accordance with ArosaPay's data retention schedule, except where retention is required by law. The Controller may request confirmation of deletion.

    13. Data Breach Notification

    In the event of a Personal Data breach, ArosaPay shall notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Incident handling procedures are documented in the Incident Response & Security Commitment.

    Notification shall include:

    • Nature and scope of the breach
    • Categories and approximate number of Data Subjects affected
    • Categories and approximate number of Personal Data records affected
    • Likely consequences of the breach
    • Measures taken or proposed to mitigate the breach
    • Contact point for further information

    ArosaPay shall cooperate with the Controller in investigating the breach and in meeting any regulatory notification obligations.

    14. Audit Rights

    The Controller may verify ArosaPay's compliance with this DPA through the following mechanisms:

    • Request reasonable documentation of security controls and processing activities
    • Request copies of independent security certifications or audit reports (where available)
    • Conduct an audit upon reasonable notice, subject to confidentiality obligations and scope limitations

    Audit limitations:

    • Audits must not disrupt ArosaPay's normal operations
    • Audits must not compromise the confidentiality or security of other customers' data
    • The Controller shall bear the costs of any audit it initiates
    • ArosaPay may offer equivalent assurance through certifications or third-party audit reports

    15. Confidentiality

    All Personal Data processed under this DPA is treated as confidential information. Access to Personal Data is limited to authorized personnel who require access for the performance of their duties and who are subject to binding confidentiality obligations.

    ArosaPay shall ensure that any person authorized to process Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.

    16. Liability

    Liability under this DPA is subject to the liability provisions and caps set forth in the Merchant Agreement.

    • Liability is limited to the extent permitted by applicable law
    • Nothing in this DPA excludes or limits liability for willful misconduct or gross negligence where such exclusion is prohibited by law
    • Each party is liable for damages caused by processing that infringes applicable data protection law

    17. Termination

    Upon termination of the Merchant Agreement or upon the Controller's written request:

    • ArosaPay shall delete or return all Personal Data to the Controller, at the Controller's election
    • Deletion includes all copies, except where retention is required by applicable law
    • Where retention is legally required, ArosaPay shall isolate and protect the retained Personal Data from further processing
    • Certification of deletion may be provided upon the Controller's request

    18. Governing Law

    This DPA is governed by the laws specified in the Merchant Agreement. To the extent that processing is subject to the GDPR or UK GDPR, the provisions of the applicable regulation shall prevail in the event of conflict with this DPA.

    Disputes arising under this DPA shall be resolved in accordance with the dispute resolution provisions of the Merchant Agreement.