PAYSECTION PRIVACY POLICY
Version 1.3
Effective Date: September 3, 2026
1. Introduction
Paysection Inc. (“Paysection,” “we,” “us,” or “our”) respects the privacy of individuals whose Personal Information is processed in connection with our websites, Platform and Services.
This Privacy Policy explains how we collect, use, disclose, retain and protect Personal Information and how individuals may exercise applicable privacy rights.
Paysection provides business-to-business payment technology and related payment, payout, reconciliation, reporting and compliance-support Services. Our Services are not directed primarily to consumers. However, in providing Services to business clients, Paysection may process information relating to client representatives, Sub-Merchants, Downstream Clients, End Users, beneficiaries, payment counterparties and other individuals.
This Privacy Policy should be read together with any applicable Platform Service Agreement, Data Processing Addendum, Online Terms and Conditions and other applicable service documentation.
For purposes of this Privacy Policy, “Personal Information” includes “Personal Data” and similar terms used under applicable privacy and data-protection laws.
2. Paysection’s Privacy Roles
2.1 Paysection Acting for a Business Client
Where Paysection Processes Personal Information solely on documented instructions of a business client for purposes such as transaction orchestration, payment-data transmission, Platform administration or related support, Paysection may act as a processor, service provider or equivalent service-provider role under applicable law.
The applicable client remains responsible for determining the purposes and lawful basis of that Processing, except to the extent applicable law provides otherwise.
2.2 Paysection Acting Independently
Paysection may separately act as an organization responsible for, or independent controller of, Personal Information where Paysection determines the relevant purposes of Processing in order to:
satisfy Paysection’s own legal or regulatory obligations;
conduct AML/CTF, KYC/KYB or sanctions compliance;
perform transaction monitoring applicable to Paysection;
identify or prevent fraud, misuse or security threats;
maintain regulatory, audit or compliance records;
administer Paysection’s relationship with a Merchant;
protect the integrity of the Platform;
establish, exercise or defend legal rights; or
comply with lawful requests from competent authorities.
Where Paysection Processes information for its own legal or regulatory obligations, that Processing is not undertaken solely on the instructions of a Merchant.
2.3 Financial-Institution Partners
Banks, regulated trust companies, trustees, electronic-money institutions, payment institutions, payment networks, processors and other Financial-Institution Partners may receive Personal Information in connection with the Services.
A Financial-Institution Partner may independently Process Personal Information where required for its own:
account administration;
trusteeship;
safeguarding;
custody or account control;
payment execution or settlement;
sanctions screening;
AML/CTF compliance;
fraud prevention;
regulatory reporting; or
other legal, regulatory or fiduciary obligations.
Such entities may have their own privacy notices and independent legal responsibilities.
3. Personal Information We May Collect
The Personal Information we collect depends on the individual, applicable Service and transaction structure.
3.1 Business and Contact Information
We may collect:
name;
business email address;
telephone number;
business or residential address where required;
job title and role;
employer or organization;
Platform account and Authorized User information; and
communications with Paysection.
3.2 Identity and Compliance Information
Where required for onboarding, identity verification, risk assessment or compliance, we may collect or receive:
date of birth;
nationality or residency information;
government-issued identification information;
copies or images of identity documents;
beneficial-ownership information;
corporate ownership or control information;
source-of-funds or source-of-wealth information where relevant;
transaction-purpose information;
sanctions-screening results;
politically exposed person or head-of-international-organization information;
compliance and risk classifications; and
other information reasonably required by applicable law or Financial-Institution Partner requirements.
Depending on the identity-verification method used, an authorized verification provider may Process facial images, liveness information, document images or biometric information.
Where this constitutes sensitive Personal Information, biometric information or special-category Personal Data under applicable law, it will be Processed only where legally permitted and subject to appropriate safeguards.
3.3 Payment and Transaction Information
We may collect or receive:
originator and beneficiary information;
account numbers and payment identifiers;
routing, transit, IBAN, SWIFT/BIC or similar information;
payment amount and currency;
transaction date and time;
transaction references;
payment purpose;
payment rail;
transaction status;
return, rejection or recall information;
settlement information; and
related transaction metadata.
3.4 Platform and Technical Information
When an individual accesses our websites or Platform, we may collect:
IP address;
device and browser information;
operating system;
authentication and login records;
API or session activity;
Platform actions;
timestamps;
security and audit logs;
approximate geographic information derived from technical information such as IP address; and
other information reasonably required to maintain Platform security and reliability.
Paysection does not collect precise device-location information unless expressly enabled for a specific feature and disclosed as required by applicable law.
3.5 Cookies and Similar Technologies
Our websites or Platform may use cookies and similar technologies for authentication, security, user preferences, Platform functionality, performance measurement and analytics.
Further information is provided in Section 11.
4. Sources of Personal Information
We may obtain Personal Information:
directly from an individual;
from a Merchant or other business client;
from an individual’s employer or organization;
from Sub-Merchants or Downstream Clients;
from identity-verification and compliance providers;
from Financial-Institution Partners;
from payment networks or processors;
from public or legally available sources;
from sanctions, PEP/HIO, corporate or regulatory databases;
through use of the Platform or website; or
where otherwise permitted or required by law.
Where a Merchant provides Personal Information to Paysection, the Merchant is responsible for having the authority, notices, consents or other lawful basis required to provide that information.
5. How We Use Personal Information
5.1 Providing the Services
We may Process Personal Information to:
establish and administer business accounts;
authenticate Platform users;
receive and process Transaction Instructions;
transmit payment information;
administer Platform ledger records;
reconcile activity;
provide reporting;
provide technical support; and
communicate operational and Service information.
5.2 Payments and Financial-Institution Services
We may Process Personal Information to:
transmit payment or payout instructions;
facilitate execution and settlement through Financial-Institution Partners;
attribute transactions and funds;
investigate returned or rejected transactions;
manage reconciliation exceptions; and
support applicable account, safeguarding, trustee or trust structures.
5.3 Compliance and Legal Obligations
We may Process Personal Information to:
conduct KYC/KYB and identity verification;
identify beneficial owners;
conduct sanctions and PEP/HIO screening;
monitor transactions;
investigate potentially suspicious or unusual activity;
assess source of funds or payment purpose where appropriate;
maintain legally required records;
prepare or submit regulatory reports where required;
respond to regulators and law-enforcement authorities; and
satisfy obligations applicable to Paysection under financial-services, anti-money-laundering and payment laws.
5.4 Security and Fraud Prevention
We may Process Personal Information to:
authenticate users;
prevent unauthorized transactions;
identify fraud or misuse;
monitor Platform integrity;
investigate incidents;
enforce access controls; and
protect Paysection, Merchants, End Users and Financial-Institution Partners.
5.5 Business Administration
We may Process Personal Information to:
manage Merchant relationships;
administer contracts and billing;
communicate operational information;
manage disputes or complaints;
conduct audits;
maintain business records; and
establish, exercise or defend legal claims.
5.6 Analytics and Service Improvement
We may use appropriate operational and usage information to understand Platform performance, identify technical issues and improve our Services.
Where reasonably practicable, information used for analytics or statistical purposes may be aggregated or de-identified.
5.7 Marketing
Paysection may send business communications concerning Paysection products or Services where permitted by applicable law.
Where consent is legally required, marketing communications will be sent only with the required consent.
Recipients may opt out using the unsubscribe method provided or by contacting Paysection.
6. Legal Bases for Processing
The applicable legal basis depends on the jurisdiction, Processing activity and circumstances.
Where the GDPR, UK GDPR or similar legislation applies, Paysection may rely on:
performance of a contract;
steps taken at an individual’s request before entering into a contract;
compliance with a legal obligation;
legitimate interests, where those interests are not overridden by applicable individual rights;
consent, where required or appropriate; or
another lawful basis available under applicable law.
Where Paysection Processes Personal Data solely as a processor for a business client, the applicable client is generally responsible for determining the lawful basis for the underlying Processing.
Paysection does not rely on blanket acceptance of this Privacy Policy as a substitute for valid consent where consent is legally required.
7. Disclosure of Personal Information
7.1 Financial-Institution Partners
We may disclose Personal Information to banks, regulated trust companies and trustees, payment institutions, electronic-money institutions, processors, correspondent institutions, clearing providers and payment networks involved in an applicable Service.
7.2 Technology and Service Providers
We may disclose Personal Information to providers supporting cloud infrastructure, software, identity verification, compliance screening, communications, security, data storage, analytics, customer support and professional services.
Where such providers Process Personal Information on Paysection’s behalf, Paysection uses contractual or other safeguards appropriate to the relationship and applicable law.
7.3 Regulatory and Government Authorities
Paysection may disclose information to regulatory, governmental, judicial or law-enforcement authorities where required or permitted by applicable law.
This may include FINTRAC, the Bank of Canada, privacy regulators, tax authorities, courts, law-enforcement agencies and sanctions authorities.
7.4 Corporate Transactions
Information may be disclosed in connection with a proposed or completed merger, acquisition, financing, restructuring, sale of assets or similar corporate transaction, subject to appropriate confidentiality and legal protections.
7.5 Professional Advisers
Information may be disclosed to auditors, lawyers, accountants, insurers and other professional advisers where reasonably necessary and subject to applicable confidentiality obligations.
Paysection does not sell Personal Information for monetary consideration.
8. International and Cross-Border Processing
Paysection operates in a cross-border payments environment. Personal Information may therefore be accessed, stored or Processed outside an individual’s province, state or country.
Information Processed outside Canada may be subject to the laws of the jurisdiction in which it is Processed and may lawfully be accessible to courts, regulators or governmental authorities in that jurisdiction.
Where Paysection remains responsible for Personal Information transferred to a service provider, Paysection uses contractual and organizational safeguards appropriate to applicable law.
Where the GDPR or UK GDPR applies, Paysection will use an appropriate international-transfer mechanism where legally required, which may include:
adequacy decisions;
European Commission Standard Contractual Clauses;
the UK International Data Transfer Addendum;
the UK International Data Transfer Agreement; or
another legally recognized transfer mechanism.
Supplementary technical, contractual or organizational safeguards may also be implemented where appropriate.
9. Data Security
Paysection maintains administrative, technical and organizational safeguards appropriate to the sensitivity of Personal Information and nature of the Processing.
Measures may include, as appropriate:
role-based access controls;
least-privilege access;
multi-factor authentication for privileged access;
encryption in transit and at rest;
system and access logging;
security monitoring;
vulnerability and patch management;
backup and recovery procedures;
incident-response procedures;
staff privacy and security training; and
vendor-risk controls.
No electronic system or method of transmission can be guaranteed to be completely secure.
Individuals should protect their credentials and promptly notify Paysection of suspected unauthorized access.
10. Retention
Paysection retains Personal Information only for as long as reasonably necessary for the purposes for which it was collected or as required or permitted by applicable law.
Retention periods vary based on the applicable Service, contractual requirements, transaction lifecycle, regulatory requirements, AML/CTF recordkeeping obligations, audit requirements, legal claims and security requirements.
Certain AML/CTF, KYC/KYB and transaction records may be required to be retained for at least five years or longer where applicable law requires.
Where Paysection Processes information solely on behalf of a Merchant, return and deletion are also subject to the applicable Data Processing Addendum.
Information may be retained following termination where required for legal, regulatory, audit, security or dispute-resolution purposes.
When information is no longer required, Paysection will securely delete, destroy, anonymize or otherwise dispose of it in accordance with applicable requirements.
11. Cookies and Tracking Technologies
Paysection may use cookies and similar technologies necessary for website or Platform operation, authentication, security and user preferences.
We may also use analytics or performance technologies where permitted by applicable law.
Where applicable law requires prior notice, choice or consent for technologies used to identify, locate or profile an individual, Paysection will provide the required notice and activation or consent mechanism.
Browser settings may permit individuals to block or delete certain cookies. Disabling necessary cookies may affect website or Platform functionality.
Where Paysection provides a dedicated cookie-preference or consent tool, that tool should be used to manage applicable non-essential cookies.
12. Personal Data Breaches
Paysection maintains procedures for identifying, assessing, containing and responding to Personal Data breaches.
Where applicable Canadian privacy law requires notification or reporting of a breach, Paysection will provide required notification to affected individuals and applicable authorities within the timeframe required by law.
Where PIPEDA applies and a breach creates a real risk of significant harm, required notifications and reports will be made as soon as feasible.
Where the GDPR or UK GDPR applies, Paysection will comply with applicable breach-notification requirements, including applicable supervisory-authority notification periods.
Where Paysection is acting as a Processor for a Merchant, Paysection will notify the applicable Merchant in accordance with the governing Data Processing Addendum.
13. Individual Privacy Rights
Depending on applicable law, individuals may have rights including the right to:
access Personal Information;
request correction;
request deletion where legally available;
withdraw consent where Processing is based on consent;
object to certain Processing;
request restriction;
request portability of eligible information;
obtain information regarding use and disclosure; and
make a complaint regarding Paysection’s Personal Information practices.
These rights are subject to applicable legal exceptions and limitations.
Where Paysection Processes Personal Information solely as a Processor for a Merchant, Paysection may refer a request to that Merchant and assist as required under the applicable Data Processing Addendum.
Paysection may require reasonable identity verification before responding to a request.
14. Automated Processing
Paysection may use automated rules and technical controls to assist with transaction validation, fraud detection, sanctions screening, compliance alerts, transaction monitoring, security and risk identification.
Not every automated alert or screening result results in an automated decision. Compliance matters may be escalated for human review depending on the circumstances.
Where applicable law provides specific rights concerning decisions based exclusively on automated Processing, Paysection will provide those rights as required.
15. Children and Minors
Paysection’s Services are designed for businesses and are not directed to children.
Paysection does not knowingly permit minors to establish business Platform accounts.
Personal Information concerning a minor may nevertheless appear in an authorized transaction, compliance record or other lawful business context.
Where such information is received, Paysection will Process it only for the applicable lawful purpose and retain or delete it in accordance with applicable legal requirements.
16. Changes to This Privacy Policy
Paysection may update this Privacy Policy from time to time to reflect changes in law, regulatory requirements, Services, technology, security practices or information-handling practices.
The current version and effective date will be published on Paysection’s website.
Where a material change requires additional notice or consent under applicable law, Paysection will provide that notice or obtain consent as required.
An update to this Privacy Policy does not by itself amend an executed Platform Service Agreement or Data Processing Addendum contrary to its terms.
17. Privacy Questions, Requests and Complaints
Paysection has designated a person responsible for its privacy compliance.
Privacy Officer
Paysection Inc.
49 High Street, 3rd Floor
Barrie, Ontario L4N 5J4
Canada
Email: info@paysection.com
Individuals may contact the Privacy Officer to ask questions, exercise applicable privacy rights or make a complaint regarding Paysection’s Personal Information practices.
Paysection will investigate privacy complaints in accordance with applicable law.
Individuals may also have the right to complain to the privacy or data-protection authority having jurisdiction over the matter.
End of Paysection Privacy Policy v1.3
© 2026 Paysection Inc. All Rights Reserved.
ADDENDUM B – DATA PROCESSING ADDENDUM (DPA)
Version 1.1
Effective Date: September 3, 2026
Status and Incorporation
This Addendum B – Data Processing Addendum (“DPA”) forms part of an applicable Platform Service Agreement or other agreement between Paysection Inc. (“Paysection” or “Processor”) and a business client (“Merchant” or “Controller”) only where this DPA is expressly incorporated, accepted or executed as part of that agreement (the “Agreement”).
When this DPA is posted publicly or provided before execution without being expressly incorporated into an Agreement, it is a convenience copy only and does not by itself amend an existing contract.
Where the Parties have executed, accepted or incorporated another version of Addendum B or another data processing agreement, that executed, accepted or incorporated version controls for that relationship.
This DPA applies where Paysection Processes Personal Data on behalf of Controller in connection with the Services and addresses applicable requirements under privacy and data-protection laws including, where applicable, PIPEDA, applicable Canadian provincial privacy legislation, the EU GDPR, UK GDPR, CCPA/CPRA, LGPD and comparable legislation (“Data Protection Laws”).
1. Definitions
“Controller Data” means Personal Data Processed by Processor on behalf of Controller under this DPA.
“Data Protection Laws” means privacy and data-protection laws applicable to Processing covered by this DPA.
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
“Personal Data” means information relating to an identified or identifiable natural person and includes “Personal Information” or equivalent terms under applicable Data Protection Laws.
“Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Controller Data.
“Process,” “Processed” and “Processing” have the meanings assigned under applicable Data Protection Laws.
“Processor” means Paysection to the extent Paysection Processes Controller Data on behalf of Controller.
“Sub-Processor” means a third party engaged by Processor to Process Controller Data on behalf of Controller.
Capitalized terms not defined in this DPA have the meanings assigned under the applicable Agreement.
2. Scope and Roles
2.1 Controller
Controller determines the purposes and means of Processing for which Paysection acts as Processor and is responsible for:
establishing a lawful basis for Processing;
providing required privacy notices;
obtaining legally required consent where applicable;
ensuring instructions given to Processor comply with Data Protection Laws;
ensuring Controller Data is lawfully collected and disclosed to Processor; and
fulfilling Controller’s own obligations under Data Protection Laws.
2.2 Processor
Processor shall Process Controller Data only:
(a) on documented instructions from Controller;
(b) as reasonably necessary to provide the applicable Services; or
(c) where required by applicable law.
Where applicable law requires Processor to Process Controller Data other than on Controller’s instructions, Processor shall inform Controller before such Processing unless legally prohibited from doing so.
2.3 Independent Processing by Paysection
Certain Processing undertaken by Paysection for its own purposes or legal obligations falls outside the Processor role governed by this DPA.
Paysection may act independently as an organization responsible for, or controller of, Personal Data where Paysection determines the relevant purposes of Processing to:
comply with AML/CTF obligations;
conduct sanctions or other regulatory screening;
conduct transaction monitoring applicable to Paysection;
prevent or investigate fraud or security incidents;
satisfy regulatory reporting or recordkeeping requirements;
comply with legal process;
administer Paysection’s own relationship with Controller; or
establish, exercise or defend legal rights.
Such independent Processing is governed by applicable Data Protection Laws and the Paysection Privacy Policy rather than Controller’s instructions under this DPA.
2.4 Financial-Institution Partners
Banks, regulated trust companies or trustees, payment institutions, electronic-money institutions, payment networks and other Financial-Institution Partners may Process Personal Data independently when acting in their own regulated, fiduciary or financial capacity, including for:
account administration;
trusteeship;
safeguarding;
custody or account control;
payment execution;
settlement;
AML/CTF compliance;
sanctions screening;
fraud prevention; or
regulatory reporting.
A Financial-Institution Partner acting independently for such purposes is not a Sub-Processor merely because its services form part of the broader payment program.
If a Financial-Institution Partner or other entity Processes Controller Data solely on behalf of Paysection in Paysection’s capacity as Processor, that entity will be treated as a Sub-Processor to the extent required by applicable Data Protection Laws.
Nothing in this DPA modifies the allocation of ownership, beneficial entitlement, legal title, trusteeship, custody, safeguarding, account control, payment authorization, payment execution or settlement responsibilities established under the Agreement or other applicable Governing Documentation.
3. Processing Instructions
Controller instructs Processor to Process Controller Data as reasonably necessary to:
provide the Services;
administer Controller’s Platform access;
receive, validate, format and transmit transaction information;
support payment and payout orchestration;
provide reconciliation and reporting;
provide technical and operational support;
maintain Platform security;
perform the activities described in Annex I; and
comply with other documented instructions agreed by the Parties.
Processor shall inform Controller if, in Processor’s reasonable opinion, an instruction infringes applicable Data Protection Laws, unless Processor is legally prohibited from doing so.
Processor may suspend the affected Processing pending resolution of such an issue.
4. Confidentiality
Processor shall ensure persons authorized to Process Controller Data:
access the information only as necessary for their responsibilities;
are subject to appropriate confidentiality obligations; and
receive appropriate privacy and security awareness or training.
Processor shall not disclose Controller Data except:
on Controller’s instructions;
as permitted by the Agreement;
to authorized Sub-Processors;
to independent Financial-Institution Partners where necessary for the applicable Service;
where required or permitted by applicable law; or
as otherwise permitted by this DPA.
5. Security Measures
Processor shall implement and maintain appropriate technical and organizational measures designed to protect Controller Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or unauthorized access.
Measures shall be proportionate to the sensitivity of Personal Data, the nature and volume of Processing, reasonably foreseeable threats, available technology, cost of implementation and applicable legal requirements.
Processor’s current categories of security measures are described in Annex II.
Processor may update individual measures from time to time, provided that such changes do not materially reduce the overall level of protection required by Data Protection Laws.
6. Sub-Processors
6.1 General Authorization
Controller grants Processor general authorization to engage Sub-Processors reasonably necessary to provide the Services.
6.2 Flow-Down Obligations
Processor shall require Sub-Processors to be subject to appropriate data-protection obligations that are no less protective in material respects than the obligations imposed on Processor under this DPA where required by applicable law.
Processor remains responsible for Sub-Processor acts and omissions to the extent required by applicable Data Protection Laws and the Agreement.
6.3 Sub-Processor Information
Processor will provide information concerning material Sub-Processing arrangements reasonably sufficient to enable Controller to assess relevant data-protection risks.
Such information may include:
type of service;
purpose of Processing;
categories of Personal Data;
relevant Processing location; and
applicable transfer or security information.
Processor is not required to publicly disclose confidential vendor identities, Financial-Institution Partner networks, routing relationships or commercially sensitive infrastructure information.
Upon written request and subject to appropriate confidentiality restrictions, Processor may disclose the identity of a particular Sub-Processor where reasonably necessary for Controller’s legitimate data-protection assessment or a binding legal or regulatory requirement.
6.4 Changes
Processor shall provide prior notice, which may be delivered by email or secure portal, of an intended addition or replacement of a material Sub-Processor where required by applicable law or the Agreement.
In urgent circumstances involving security, continuity or legal requirements, Processor may engage a replacement on shorter notice and notify Controller without undue delay thereafter.
6.5 Objections
Controller may object to an intended material Sub-Processor on reasonable and documented data-protection grounds within ten (10) days following applicable notice.
The Parties shall work in good faith to address the objection, including where reasonably practicable through additional safeguards, configuration changes, an alternative provider or another reasonable solution.
Where no commercially reasonable solution is available, Controller may suspend or terminate only the affected Service without penalty to the extent permitted by the Agreement or required by applicable Data Protection Laws.
This Section does not create a right to terminate unrelated Services or the entire Agreement unless the Agreement expressly provides otherwise.
6.6 Confidentiality of Provider Information
Non-public information concerning Sub-Processors, infrastructure or provider arrangements constitutes Confidential Information.
Controller shall use such information only for legitimate regulatory, compliance or data-protection purposes and shall not publicly disclose or use it to interfere with Processor’s commercial relationships.
This restriction does not prevent disclosure required by applicable law or a competent Regulatory Authority.
7. Personal Data Breaches
Processor shall notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Controller Data and, where reasonably feasible, within 48 hours.
The notification will include information reasonably available at the time concerning:
the nature of the breach;
affected categories of Personal Data;
affected categories and approximate number of Data Subjects where known;
likely consequences;
mitigation or remediation measures taken or proposed; and
an appropriate contact point.
Processor may provide information in phases as further facts become available.
Processor shall reasonably cooperate with Controller in investigation, mitigation and legally required notifications.
Notification of a Personal Data Breach does not constitute an admission of fault or liability.
Controller remains responsible for determining whether notification to Data Subjects or supervisory authorities is required where Controller is legally responsible for such notification.
8. Data Subject Requests
Taking into account the nature of Processing, Processor shall provide reasonable assistance to Controller in responding to legally valid Data Subject requests relating to Controller Data, including:
access;
correction or rectification;
deletion or erasure;
restriction;
objection; or
portability,
to the extent applicable under relevant Data Protection Laws.
If Processor receives a request directly from a Data Subject concerning Controller Data for which Processor acts solely for Controller, Processor may refer the Data Subject to Controller, notify Controller and refrain from substantively responding unless authorized by Controller or required by law.
Processor may respond independently insofar as a request concerns Personal Data for which Paysection acts independently.
9. Regulatory Assistance and DPIAs
Taking into account the nature of Processing and information available to Processor, Processor shall provide reasonable assistance, at Controller’s cost where permitted and appropriate, with:
data-protection impact assessments;
prior consultation with supervisory authorities;
privacy-regulator inquiries;
records of Processing;
security assessments; and
other Controller obligations under applicable Data Protection Laws.
Processor is not required to disclose privileged, proprietary, third-party confidential or security-sensitive information beyond what is legally required.
10. International Transfers
Where Processor transfers or permits access to Controller Data across national borders, Processor shall comply with applicable international-transfer requirements.
Where Personal Data subject to the EU GDPR is transferred to a jurisdiction requiring an Article 46 transfer mechanism, applicable European Commission Standard Contractual Clauses may be incorporated as required.
Where Personal Data subject to the UK GDPR is transferred internationally, the UK International Data Transfer Addendum, International Data Transfer Agreement or another valid mechanism may apply.
Processor may rely upon:
adequacy determinations;
Standard Contractual Clauses;
approved addenda;
recognized certifications or frameworks; or
another lawful transfer mechanism.
Supplementary safeguards will be implemented where required and appropriate.
Controller remains responsible for ensuring that its disclosure of Personal Data to Processor is lawful.
11. Return, Deletion and Retention
Upon termination of the affected Services, Processor shall, at Controller’s election and subject to the Agreement:
return Controller Data reasonably available for return; and/or
delete Controller Data,
unless applicable law requires or permits continued retention.
Backup copies may be deleted in accordance with Processor’s ordinary backup-retention cycles.
Notwithstanding a return or deletion request, Paysection may retain Personal Data to the extent reasonably necessary to:
comply with AML/CTF requirements;
comply with financial-services or payments regulation;
comply with accounting or tax laws;
satisfy audit or regulatory requirements;
maintain security or incident records;
comply with legal process; or
establish, exercise or defend legal rights.
Information retained for these purposes remains subject to appropriate safeguards.
Processor shall provide reasonable confirmation of deletion upon written request where appropriate.
12. Audit and Information Rights
Processor shall make available information reasonably necessary to demonstrate compliance with this DPA and applicable Processor obligations under Data Protection Laws.
Subject to the Agreement, Controller may conduct or commission an audit:
no more than once during any 12-month period;
on at least 30 days’ written notice;
during normal business hours;
through personnel or an independent auditor subject to confidentiality obligations;
in a manner designed to minimize operational disruption; and
only to the extent reasonably necessary to assess compliance with this DPA.
The annual limitation or notice period does not apply where:
a competent regulator requires otherwise;
applicable law requires otherwise;
a material Personal Data Breach reasonably justifies more immediate review; or
the Parties otherwise agree.
Processor may satisfy an audit request where reasonably appropriate by providing policies, certifications, security summaries, independent audit reports, compliance questionnaires or equivalent evidence.
An audit does not entitle Controller to access:
unrelated financial records;
unrelated client information;
payment routing or Financial-Institution Partner information unrelated to data protection;
source code;
vulnerability or penetration-testing details where disclosure would create security risk;
privileged material; or
other third-party Confidential Information,
except where disclosure is legally required.
Each Party bears its own audit costs unless otherwise provided in the Agreement or applicable law.
13. Government and Regulatory Requests
Where Processor receives a binding governmental, regulatory or law-enforcement request concerning Controller Data, Processor shall:
assess the validity and scope of the request;
disclose only information reasonably required to comply;
notify Controller where legally permitted and appropriate; and
challenge or seek clarification where required by applicable Data Protection Laws and reasonably appropriate.
Nothing in this DPA requires Processor to violate applicable law, a court order, regulatory direction or legal prohibition on disclosure.
14. Records and Accountability
Processor shall maintain records relating to Processing covered by this DPA where required by applicable Data Protection Laws.
Processor shall maintain reasonable policies and procedures addressing:
access management;
information security;
incident response;
retention;
vendor management; and
privacy compliance.
Processor shall cooperate reasonably with competent supervisory authorities where legally required.
15. Liability
Liability arising under this DPA is subject to the exclusions, caps, indemnities, procedures and other limitations established by the Agreement.
Nothing in this DPA creates a higher or separate liability cap unless expressly stated in the Agreement.
Nothing excludes or limits liability where such exclusion or limitation is prohibited by applicable law.
16. Conflict and Precedence
This DPA governs only Processing of Personal Data within its scope.
Where the Agreement establishes an order of precedence, that order controls except to the extent Data Protection Laws require otherwise.
Where the Agreement provides that an Addendum prevails with respect to its specific subject matter, this DPA prevails only with respect to data-protection obligations within its scope.
Nothing in this DPA modifies or overrides the allocation of:
ownership of funds;
beneficial entitlement;
legal title;
trusteeship;
custody;
safeguarding;
account control;
payment authorization;
payment execution; or
settlement
under the Agreement, trust documentation, account documentation or other applicable Governing Documentation.
Where Controller has executed, accepted or incorporated another version of Addendum B or another data processing agreement with Paysection, that version prevails over any publicly posted convenience copy.
17. Changes to Addendum B
Where this DPA forms part of an executed Agreement, amendments are governed by the amendment and notice provisions of that Agreement.
Paysection may update a publicly posted convenience copy to reflect changes in law, regulatory guidance, security practices or Services.
An update to a publicly posted convenience copy does not amend or replace a separately executed, accepted or incorporated DPA except to the extent the applicable Agreement expressly permits such amendment.
18. Governing Law
The governing-law and dispute-resolution provisions of the Agreement apply to this DPA.
Annex I – Processing Details
Subject Matter and Purpose
Processing of Personal Data in connection with Paysection’s Platform and approved payment, payout, transaction-orchestration, reconciliation, reporting and related support Services.
Duration
Processing occurs for the duration of the applicable Services and any additional legally required retention period.
Nature of Processing
Processing may include:
collection;
receipt;
validation;
transmission;
storage;
organization;
retrieval;
consultation;
reconciliation;
reporting;
deletion; and
other Processing reasonably necessary to provide the Services on Controller’s instructions.
Categories of Data Subjects
Depending on the Service:
Controller personnel and Authorized Users;
Sub-Merchant personnel;
Downstream Clients who are natural persons;
End Users;
beneficiaries;
payment originators;
payment recipients; and
other individuals whose information is included in authorized transactions.
Categories of Personal Data
Depending on the Service:
identity and contact information;
business role and organization information;
beneficiary and payment information;
bank-account and payment identifiers;
transaction references and metadata;
Platform-user and authentication information;
technical and security logs;
compliance-related information supplied by Controller; and
other information reasonably necessary for the approved Service.
Sensitive or Special Categories
Special-category or sensitive Personal Data is not ordinarily required for basic payment orchestration.
Approved identity-verification or compliance processes may nevertheless involve sensitive identification or biometric information where lawful and appropriate.
Controller shall not instruct Processor to Process special-category or sensitive Personal Data beyond what is reasonably necessary for an approved Service unless an appropriate lawful basis and safeguards have been established.
Frequency
Processing may occur continuously during the term of the applicable Services.
Annex II – Technical and Organizational Measures
Paysection maintains a security program designed to provide protection appropriate to the nature and sensitivity of Controller Data.
Measures include, as applicable to the relevant systems:
Access Management
role-based access controls;
least-privilege principles;
unique user accounts;
multi-factor authentication for privileged or administrative access;
periodic access reviews; and
prompt removal of unnecessary access.
Encryption and Transport Security
encryption of data in transit using TLS 1.2 or higher, or an industry-standard successor;
strong encryption of sensitive data at rest where appropriate and technically supported;
secure handling of authentication secrets and credentials; and
encryption or equivalent protection for applicable backups.
Systems and Network Security
secure configuration standards;
vulnerability management;
security patching;
endpoint protections;
network protections appropriate to system architecture; and
controls designed to reduce unauthorized access.
Logging and Monitoring
logging of relevant administrative and security activity;
security monitoring;
review of material security events;
anomaly or threat detection appropriate to the relevant environment; and
incident-escalation procedures.
Business Continuity and Backups
regular backups of applicable production information;
recovery procedures;
periodic backup or recovery testing where appropriate;
business-continuity planning; and
disaster-recovery procedures appropriate to critical Services.
Personnel Controls
confidentiality obligations;
role-based access restrictions;
privacy and security awareness;
security procedures; and
appropriate offboarding controls.
Vendor Management
due diligence appropriate to vendor risk;
contractual data-protection requirements where applicable;
Sub-Processor oversight; and
controls relating to onward disclosure or international transfers.
Data Minimization and Retention
collection and Processing limited to reasonably necessary information;
role-based access restrictions;
retention rules;
deletion or anonymization procedures; and
controls around data export where appropriate.
Processor may replace a specific technical measure with another measure providing an equivalent or higher overall level of protection where reasonable in light of technological development, legal requirements and operational needs.
Annex III – Sub-Processor Information
Paysection maintains an internal register of material Sub-Processing arrangements.
Information concerning material Sub-Processors may be provided to Controller in accordance with Section 6.
Non-public Sub-Processor information constitutes Paysection Confidential Information.
Financial-Institution Partners acting independently in a regulated payment, settlement, account, trustee, safeguarding, AML/CTF or similar capacity are governed by Section 2.4 and are not classified as Sub-Processors merely because they perform those independent functions.
End of Addendum B – Data Processing Addendum v1.1
© 2026 Paysection Inc. All Rights Reserved.

