Legal
Data Processing Agreement
GDPR-Compliant Addendum. This DPA forms part of the Merchant Agreement and governs the processing of Personal Data in connection with ArosaPay's transaction processing services.
Last updated: February 2026
1. Purpose
This Data Processing Agreement ("DPA") governs the processing of Personal Data in connection with ArosaPay's transaction processing services. This DPA forms part of the Merchant Agreement between ArosaPay and the Merchant.
This DPA ensures compliance with:
- EU General Data Protection Regulation (GDPR)
- UK GDPR (where applicable)
- Applicable data protection laws in relevant jurisdictions
2. Role of the Parties
For transaction data processed under the Merchant Agreement, the following roles apply:
- Merchant is the Data Controller — determines the purposes and means of processing Personal Data
- ArosaPay acts as Data Processor — processes Personal Data on behalf of the Controller
In certain limited cases, ArosaPay may act as an independent Controller as required by law, including for fraud monitoring, AML compliance, and regulatory reporting obligations.
3. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person
- "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means
- "Data Subject" means an identified or identifiable natural person whose Personal Data is processed
- "Sub-Processor" means a third party engaged by ArosaPay to process Personal Data on behalf of the Controller
4. Subject Matter & Duration
Subject Matter
Processing necessary to perform transaction processing services, including:
- Execute payment transactions
- Secure funds within the conditional release framework
- Administer dispute resolution proceedings
- Execute payout operations to merchants
- Perform risk assessment and fraud monitoring
Duration
Processing continues for the term of the Merchant Agreement and any legally required retention period thereafter.
5. Categories of Data
ArosaPay may process the following categories of Personal Data:
- Buyer name and merchant name
- Phone number and email address
- Transaction ID and payment reference
- IP address and device metadata
- Dispute documentation and correspondence
ArosaPay does not process special category data (as defined under Article 9 GDPR) unless voluntarily submitted by a Data Subject in dispute documentation. Where such data is received, it is processed solely for dispute resolution purposes.
6. Purpose of Processing
Personal Data is processed solely for the following purposes:
- Transaction orchestration and payment lifecycle management
- Ledger recording and reconciliation
- Conditional release logic and buyer confirmation workflows
- Dispute administration and evidence review
- Anti-money laundering (AML) monitoring
- Fraud detection and prevention
- Regulatory compliance and reporting obligations
Processing is not performed for unrelated marketing, profiling, or commercial purposes unless separately consented to by the Data Subject. See the Privacy Policy for details on data handling practices.
7. Processor Obligations
ArosaPay shall:
- Process Personal Data only on documented instructions from the Controller, unless required by applicable law
- Ensure that all personnel authorized to process Personal Data are subject to confidentiality obligations
- Implement appropriate technical and organizational security measures
- Not sell, rent, or otherwise commercially exploit Personal Data
- Not combine Personal Data with datasets unrelated to the services provided under the Merchant Agreement
- Assist the Controller in responding to Data Subject requests in accordance with applicable data protection law
- Provide reasonable assistance to the Controller in ensuring compliance with data protection impact assessments and prior consultation obligations
8. Security Measures
ArosaPay maintains technical and organizational security measures appropriate to the risk of processing. Full security documentation is available in the Security & Funds Safeguarding documentation.
Measures include:
- Encryption in transit using TLS
- Encryption at rest for stored Personal Data
- Role-based access control (RBAC) with least-privilege principles
- Multi-factor authentication (MFA) for internal access to production systems
- Audit logging of access to Personal Data
- Immutable transaction ledger for data integrity
- Secure key management and rotation procedures
- Incident response procedures reviewed and tested periodically
Security measures are reviewed periodically and updated in response to identified risks, technological developments, and regulatory guidance.
9. Sub-Processors
ArosaPay may engage Sub-Processors to assist in providing transaction processing services. Sub-Processors may be engaged for:
- Cloud infrastructure hosting and data storage
- Payment processing and payout execution via regulated PSP partners
- Identity verification and KYC services
- Application monitoring and security services
Sub-Processor governance:
- ArosaPay conducts due diligence on all Sub-Processors prior to engagement
- Written data protection obligations equivalent to this DPA are imposed on all Sub-Processors
- A current list of active Sub-Processors is maintained and available to the Controller upon request
- The Controller will be notified of any intended changes to Sub-Processors, with reasonable opportunity to object
10. International Transfers
Where Personal Data is transferred outside the European Economic Area (EEA) or the United Kingdom, ArosaPay shall ensure that appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) as adopted by the European Commission
- UK International Data Transfer Agreement or UK Addendum to the EU SCCs, where applicable
- Equivalent lawful transfer mechanisms recognized under applicable data protection law
Transfers occur only where necessary for the provision of transaction processing services. ArosaPay will provide information regarding the transfer mechanism upon request.
11. Data Subject Rights
Upon request from the Controller, ArosaPay shall provide reasonable assistance in responding to Data Subject requests, including:
- Right of access — confirmation and copy of Personal Data processed
- Right to rectification — correction of inaccurate Personal Data
- Right to erasure — deletion where no legal retention obligation applies
- Right to restriction — limitation of processing in specified circumstances
- Right to data portability — provision of Personal Data in structured, machine-readable format
- Right to object — cessation of processing where based on legitimate interests
Direct requests:
Where ArosaPay receives a request directly from a Data Subject, ArosaPay shall promptly notify the Controller and shall not respond directly to the Data Subject unless legally required to do so.
12. Data Retention
Transaction records and associated Personal Data are retained:
- For the duration of the contractual relationship with the Controller
- For statutory compliance periods as required by applicable law (including tax, AML, and financial record-keeping obligations)
- For fraud prevention analysis where proportionate and documented
Upon termination:
Personal Data may be deleted or anonymized in accordance with ArosaPay's data retention schedule, except where retention is required by law. The Controller may request confirmation of deletion.
13. Data Breach Notification
In the event of a Personal Data breach, ArosaPay shall notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Incident handling procedures are documented in the Incident Response & Security Commitment.
Notification shall include:
- Nature and scope of the breach
- Categories and approximate number of Data Subjects affected
- Categories and approximate number of Personal Data records affected
- Likely consequences of the breach
- Measures taken or proposed to mitigate the breach
- Contact point for further information
ArosaPay shall cooperate with the Controller in investigating the breach and in meeting any regulatory notification obligations.
14. Audit Rights
The Controller may verify ArosaPay's compliance with this DPA through the following mechanisms:
- Request reasonable documentation of security controls and processing activities
- Request copies of independent security certifications or audit reports (where available)
- Conduct an audit upon reasonable notice, subject to confidentiality obligations and scope limitations
Audit limitations:
- Audits must not disrupt ArosaPay's normal operations
- Audits must not compromise the confidentiality or security of other customers' data
- The Controller shall bear the costs of any audit it initiates
- ArosaPay may offer equivalent assurance through certifications or third-party audit reports
15. Confidentiality
All Personal Data processed under this DPA is treated as confidential information. Access to Personal Data is limited to authorized personnel who require access for the performance of their duties and who are subject to binding confidentiality obligations.
ArosaPay shall ensure that any person authorized to process Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.
16. Liability
Liability under this DPA is subject to the liability provisions and caps set forth in the Merchant Agreement.
- Liability is limited to the extent permitted by applicable law
- Nothing in this DPA excludes or limits liability for willful misconduct or gross negligence where such exclusion is prohibited by law
- Each party is liable for damages caused by processing that infringes applicable data protection law
17. Termination
Upon termination of the Merchant Agreement or upon the Controller's written request:
- ArosaPay shall delete or return all Personal Data to the Controller, at the Controller's election
- Deletion includes all copies, except where retention is required by applicable law
- Where retention is legally required, ArosaPay shall isolate and protect the retained Personal Data from further processing
- Certification of deletion may be provided upon the Controller's request
18. Governing Law
This DPA is governed by the laws specified in the Merchant Agreement. To the extent that processing is subject to the GDPR or UK GDPR, the provisions of the applicable regulation shall prevail in the event of conflict with this DPA.
Disputes arising under this DPA shall be resolved in accordance with the dispute resolution provisions of the Merchant Agreement.