Data Processing Agreement


Welcome to our Data Processing Agreement page, where we outline the terms and conditions governing the processing of personal data in compliance with data protection regulations. This agreement is designed to establish a clear and transparent framework for how we handle and safeguard your personal data when you utilize our payment gateway services. We are committed to ensuring the privacy and security of your personal information, and this agreement serves as a commitment to protect your rights and interests. In this document, we will define the roles and responsibilities of both parties involved in the data processing activities and clarify the purposes for which your data is processed.

Data Controller

The Data Controller is the entity responsible for determining the purposes and means of processing personal data within the scope of our payment gateway services. The Data Controller is responsible for collecting and processing certain types of personal data required for the initiation and completion of payment transactions. We are committed to processing your personal data in compliance with applicable data protection laws and regulations and taking measures to ensure its security and confidentiality. The Data Controller is responsible for defining the lawful basis for processing, implementing data protection policies, and responding to data subject requests in accordance with this Data Processing Agreement. 

Data Processor

The Data Processor is the entity responsible for processing personal data on behalf of the Data Controller The Data Processor acts strictly in accordance with the instructions provided by the Data Controller and solely for the purposes defined in this agreement. The Data Processor is committed to processing personal data in compliance with applicable data protection laws and regulations, maintaining the security and confidentiality of the data entrusted to them.

Personal Data

Personal data, as defined in this Data Processing Agreement, refers to any information related to an identified or identifiable natural person, known as a data subject. Examples of personal data that may be processed within the scope of our payment gateway services include names, contact details, financial information, and transaction-related data. It is essential to note that personal data is processed solely for specific and legitimate purposes, as outlined in this agreement, and in compliance with applicable data protection laws and regulations. The protection and responsible handling of personal data are paramount to us, and this agreement sets forth the terms and conditions under which such data is processed in the context of our payment gateway services.

Processing Activities

The processing activities outlined in this Data Processing Agreement encompass all actions and operations performed on personal data within the framework of our payment gateway services. These activities may include the collection, recording, organization, structuring, storage, retrieval, use, disclosure, and deletion of personal data, among others. The processing of personal data is carried out exclusively for specific and lawful purposes defined by the Data Controller, ensuring that it aligns with the requirements of data protection laws and regulations. 

Data Security Measures

Data security is of paramount importance to us, and we have implemented a range of robust measures to safeguard personal data processed within the scope of our payment gateway services. These security measures include encryption, access controls, firewalls, and regular security assessments, all aimed at protecting personal data from unauthorized access, disclosure, alteration, or destruction. We are committed to ensuring the confidentiality, integrity, and availability of personal data and have established a data breach response plan in case of any security incidents. Our personnel are trained in data protection best practices, and we conduct regular security audits to assess the effectiveness of our security measures.

Confidentiality

Confidentiality is a fundamental principle governing our data processing activities within the context of this Data Processing Agreement. We are committed to maintaining the strictest confidentiality regarding all personal data entrusted to us, ensuring that it is accessible only to authorized personnel for legitimate processing purposes. Our employees and any subcontractors involved in data processing are bound by strict confidentiality agreements to safeguard personal data from unauthorized disclosure or use. Confidentiality extends to all phases of data processing, from collection and storage to transmission and eventual deletion, in accordance with the terms specified in this agreement.

Data Subject Rights

Data subjects have certain rights regarding the processing of their personal data, as outlined in this Data Processing Agreement and in compliance with applicable data protection laws. These rights include the right to access, rectify, and delete personal data, as well as the right to restrict or object to specific processing activities. Data subjects also have the right to receive their personal data in a structured, commonly used, and machine-readable format when applicable. We are committed to facilitating the exercise of these rights by data subjects and will promptly respond to any requests submitted in accordance with the procedures defined in this agreement.

Data Breach Response

In the event of a data breach, we have established a comprehensive data breach response plan to promptly and effectively address the situation. Our response plan includes procedures for identifying and assessing the breach, notifying the appropriate authorities, and communicating with affected data subjects, if necessary. We are committed to taking all necessary steps to mitigate the impact of a data breach, including implementing remedial measures and preventing further unauthorized access.

Sub Processing 

We may engage the services of sub-processors to assist in the processing of personal data within the scope of our payment gateway services, as outlined in this Data Processing Agreement. Sub-processors are carefully selected and assessed to ensure they meet the same stringent data protection standards and obligations as specified in this agreement. Our use of sub-processors is always subject to the prior written consent of the Data Controller and in compliance with applicable data protection laws.

International Data Transfers 

International data transfers may occur when personal data is processed or stored in locations outside the jurisdiction in which the Data Controller operates. We commit to ensuring that any international data transfers comply with applicable data protection laws, including implementing appropriate safeguards as required. These safeguards may include utilizing standard contractual clauses, binding corporate rules, or relying on the data protection mechanisms recognized by relevant data protection authorities. 

Audit Rights 

The Data Controller reserves the right to audit our data processing activities to verify compliance with the terms and conditions of this Data Processing Agreement and applicable data protection laws. Audit requests must be submitted in writing and should specify the scope, purpose, and timeframe of the audit. We will cooperate fully with the Data Controller's audit activities, providing access to relevant documentation and information as required. Audits will be conducted in a manner that minimizes disruption to our operations while ensuring transparency and accountability in data processing.

Deletion of Data

Personal data processed within the scope of our payment gateway services will be retained only for as long as necessary to fulfill the purposes outlined in this Data Processing Agreement. Upon the expiry of the data retention period or upon request from the Data Controller, we will ensure the secure and complete deletion of personal data, including any copies or backups. Deletion of data will be carried out using secure methods to prevent accidental or unlawful destruction, loss, alteration, or disclosure.

Retention of Data 

Personal data processed within the framework of our payment gateway services will be retained only for as long as necessary to achieve the purposes outlined in this Data Processing Agreement. The retention period may vary depending on the specific processing activity, regulatory requirements, and the Data Controller's instructions. When personal data is no longer required for the defined purposes, we will securely delete or anonymize the data, ensuring that it is no longer identifiable or accessible.

Notification Obligations 

In the event of a personal data breach that poses a risk to the rights and freedoms of data subjects, we are committed to promptly notifying the Data Controller of such breach. Notifications will include all relevant information about the nature of the breach, its potential consequences, and the measures taken or proposed to address the breach. We will cooperate fully with the Data Controller to investigate and mitigate the breach and to take necessary steps to prevent its recurrence. 

Liability 

Our liability is limited to the extent permitted by applicable data protection laws and the terms and conditions of this Data Processing Agreement. We are responsible for processing personal data in accordance with the Data Controller's instructions and the obligations set forth in this agreement. We shall not be held liable for any indirect, incidental, special, or consequential damages arising from the processing of personal data, including, but not limited to, loss of profits, revenue, or data. Our liability is further contingent upon the Data Controller's compliance with their obligations under data protection laws and regulations. 

Indemnification

The Data Controller agrees to indemnify and hold the Data Processor harmless against any claims, losses, or liabilities arising from the Data Controller's breach of their obligations under this Data Processing Agreement or any applicable data protection laws. This indemnification includes, but is not limited to, legal fees, costs, and expenses incurred by the Data Processor in defending against such claims or liabilities. The Data Controller's obligation to indemnify the Data Processor extends to any breaches of data protection laws, unauthorized processing, or failure to comply with the terms of this agreement. The Data Processor agrees to promptly notify the Data Controller of any potential claims, allowing the Data Controller the opportunity to take appropriate measures to address the situation. 

Governing Law

This Data Processing Agreement shall be governed by and construed in accordance with the laws of India. Any disputes arising from or related to this agreement shall be subject to the exclusive jurisdiction of Indian courts. 

Changes to the Agreement

We reserve the right to make changes and updates to this Data Processing Agreement to ensure its alignment with evolving data protection laws and our business practices. Any modifications to this agreement will be communicated to the Data Controller through written notice or via electronic means, providing reasonable advance notice when possible. Failure to object to the proposed changes within a reasonable timeframe will be deemed as the Data Controller's acceptance of the revised terms.