This Data Processing Agreement (“DPA”) sets out a legally binding arrangement between (Website Name), referred to as the “Data Processor,” and the entity accepting these terms, referred to as the “Data Controller.” It regulates the Processor’s Processing of Personal Data in connection with the digital payment services provided.

Roles of the Parties

The Controller determines the purpose and lawful basis for Processing Personal Data and remains accountable for complying with all Applicable Data Protection Laws.

The Processor shall process Personal Data strictly in accordance with the documented instructions of the Controller and solely for the purpose of delivering digital payment services.

Scope of Processing

The Processor shall process Personal Data exclusively for:

  • Payment transaction initiation, authorization, and settlement
  • KYC (Know Your Customer) verification and fraud prevention
  • Customer authentication (including two-factor authentication)
  • Transaction reporting and reconciliation
  • Compliance with RBI and applicable payment network regulations

Security Measures

The Processor shall implement appropriate technical and organizational safeguards, including:

  • Adherence to recognized industry security standards for the storage, processing, and transmission of cardholder information.
  • Encryption of data both in transit and at rest
  • Multi-factor authentication for system access
  • Secure management of encryption keys
  • Routine vulnerability assessments and penetration testing

The Processor shall ensure that its personnel are bound by strict confidentiality obligations and receive training in recognized data security practices.

Data Subject Rights

The Processor shall support the Controller in responding to Data Subject requests under Applicable Laws, including:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to data portability
  • Right to restrict or object to Processing

Subprocessors

  • The Processor shall not appoint any Subprocessor without obtaining prior written consent from the Controller.
  • All authorized Subprocessors must enter into written agreements that impose data protection obligations at least equivalent to those set out in this DPA.

Data Breach Notification

The Processor shall inform the Controller within 24 hours of becoming aware of any Personal Data Breach.

Such notification shall include:

  • The nature of the breach
  • The categories and approximate number of affected Data Subjects
  • Actions taken to contain and mitigate the breach
  • Measures proposed to prevent recurrence

Audit & Compliance

Upon reasonable notice, the Controller may audit the Processor’s compliance with this DPA. The Processor shall provide access to relevant documentation, internal policies, and certifications (including reports demonstrating adherence to applicable security standards).

Data Retention & Deletion

Personal Data shall be retained only for the duration necessary to support payment processing activities and meet legal requirements (including RBI-mandated retention obligations).

Upon termination of services, the Processor shall securely delete or return all Personal Data unless continued retention is legally required.

Legal & Regulatory Changes

The Processor shall promptly notify the Controller of any legal or regulatory developments that may impact its ability to process Personal Data in accordance with this Agreement.

Liability & Indemnification

Each Party shall be responsible for damages resulting from its own breach of this Agreement. The Processor agrees to indemnify the Controller against fines, claims, or losses arising from failure to comply with applicable data protection obligations.

Governing Law & Dispute Resolution

This Agreement shall be governed by and interpreted in accordance with the laws of India. Any disputes arising from this Agreement shall fall under the exclusive jurisdiction of the courts in India.

Amendments

Any modifications to this Agreement must be documented in writing and executed by both Parties.

Acknowledgment and Acceptance

By entering into this Agreement, both Parties confirm that they understand and agree to the terms set forth in this Data Processing Agreement.