Privacy

The Privacy area demonstrates EBANX's commitment to protecting personal data and respecting individuals' privacy rights. Here you can find our Privacy Notice, Cookie Notice, Data Processing Agreement (DPA), and other privacy-related documentation explaining how we collect, use, share, store, and safeguard personal information across our products and services. Our privacy program is designed to ensure transparency and compliance with applicable data protection laws and regulations.

DATA PROCESSING AGREEMENT

Effective Date: 2026年5月30日

This Data Processing Agreement (“DPA”) is an addendum to and is incorporated into the Merchant Agreement ("Agreement") between the Merchant and EBANX, referred to jointly as “Parties” or individually as “Party”, and applies to activities involving the Processing of Personal Data (as defined below) performed in connection with the Agreement and is an integral part of the Agreement for all legal purposes.


Any capitalized terms not otherwise defined in this DPA shall have the meaning given thereto in the DPA or the Applicable Laws. Except as modified below, the terms of the Agreement shall remain in full force and effect.

1. Definitions

1.1. For the purposes of this document, the terms defined below, whether in the singular or plural, shall have the following meanings:


1.1.1.“Supervisory Authorities” means any authority, including judicial authorities, vested with powers to inspect, prosecute, adjudicate and ensure compliance with the Applicable Data Protection Laws.


1.1.2. “Employee” means any employee, staff member, including third-party contractors, representatives or designees, whether paid or unpaid, acting on a full-time or part-time basis, who acts on behalf of either Party.


1.1.3. "Agreement" means the Services Agreement, including its schedules and any addenda, which establish the terms and conditions for the provision of services by EBANX to the Merchant.

1.1.4. “Controller” means the Party responsible for the main decisions regarding the Processing of Personal Data. 


1.1.5. "Merchant Data" means the Personal Data that EBANX processes by reason of the Agreement, including Employee, business partners and the Merchant’s end consumers’ data. 


1.1.6. “Applicable Data Protection Laws” means any applicable law, regulation, directive or other binding requirements, each as may be implemented, amended, extended, replaced or re-enacted from time to time, including, but not limited to, the Data Protection Requirements.


1.1.7. “Processor” means any natural or legal person that processes Personal Data on behalf of and upon the instructions of the Controller, without the power to determine the purposes of the Processing.

1.1.8.  “Data Protection Requirements” means, as applicable: (i) AMET Data Protection Requirements; (ii) APAC Data Protection Requirements; (iii) European Data Protection Requirements; (iv) LATAM Data Protection Requirements; (v) any requirements established by the CCPA (California Consumer Privacy Act); (vi) mandatory industry rules and standards, including, as applicable, the Payment Card Industry Data Security Standard (“PCI-DSS”) and other mandatory industry standards; and (vii) any and all other applicable laws or regulations related to data protection, data security, marketing, privacy or Processing of Personal Data.


1.1.9. “AMET Data Protection Requirements” means the Applicable Data Protection Laws in the countries of Africa, the Middle East and Turkey.


1.1.10. “APAC Data Protection Requirements” means the Applicable Data Protection Laws in the countries of Asia (excluding the countries of the Middle East) and in the countries bordering the Pacific Ocean on the Asian side (including Australia, Hong Kong, Japan, India, Indonesia, Malaysia, New Zealand, the Philippines, Singapore, South Korea, Thailand, Taiwan and Vietnam).


1.1.11. “European Data Protection Requirements” means the Applicable Data Protection Laws in the European Union (“EU”), the European Economic Area (“EEA”), Switzerland and the United Kingdom (“UK”), including Regulation (EU) 2016/679 (“GDPR”), Directive 2002/58/EC, Directive 2009/136/EC and the UK GDPR, together with any local, amending or replacement legislation in any EU Member State or in the United Kingdom. For the purposes of this DPA, “UK GDPR” means the GDPR as amended and incorporated into United Kingdom law under the UK European Union (Withdrawal) Act 2018.


1.1.12. “LATAM Data Protection Requirements” means the Applicable Data Protection Laws in the countries of South America, Central America and Mexico.


1.1.13. “Services” means the set of activities to be performed by EBANX in accordance with the Agreement, including payment processing, fraud prevention and related services.


1.1.14. “Sub-processor” means any natural or legal person engaged by the Processor to assist it in the Processing of Personal Data carried out on behalf of the Controller. 


1.1.15. "Data Processing” means any operation performed with Personal Data, such as collection, production, receipt, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, deletion, assessment or control of information, modification, communication, transfer, dissemination and extraction.


1.1.16. “Security Incident” means any confirmed adverse event related to the breach of confidentiality, integrity, and/or availability of Merchant Data.

2. Jurisdiction - Specific Terms

2.1. The Parties, as applicable, shall observe the specific requirements of each jurisdiction where the Services are provided. Accordingly:

a) If the Services are provided in the countries of South America, Central America and Mexico, the LATAM Data Protection Requirements shall apply and the provisions of “Schedule A - LATAM Terms” shall be observed.

b) If the Services are provided in the countries of Africa, the Middle East and Turkey, the AMET Data Protection Requirements shall apply and the provisions of “Schedule B - AMET Terms” shall be observed.

c) If the Services are provided in the countries of Asia, including, but not limited to, Hong Kong, India, Indonesia, Pakistan, Malaysia, the Philippines, Singapore, Thailand, Taiwan and Vietnam, the APAC Data Protection Requirements shall apply and the provisions of “Schedule C - APAC Terms” shall be observed.

d) If the Services are provided in the EU, the EEA, Switzerland and the UK, the European Data Protection Requirements shall apply and the provisions of “Schedule D - European Region Terms” shall be observed.

2.2. If there are material changes to the Applicable Data Protection Laws that, in any way and for any reason, modify the terms agreed herein, or if, in the course of performing the Services, additional requirements to be complied with are identified, the Parties undertake to negotiate the new terms in good faith, making the necessary changes so that any and all Processing of Personal Data within the scope of the Agreement complies with the Applicable Data Protection Laws.


3. Processing of Personal Data

3.1. Roles of the Parties. The provision of the Services by EBANX requires the sharing of Personal Data between the Parties. In this regard, the Merchant is the Controller of the Merchant Data and acknowledges that EBANX is an independent Controller of the Personal Data related to Processing activities connected with the performance of the Services, including the processing of financial transactions, anti-money laundering and counter-terrorism financing, fraud prevention and detection, compliance with legal and regulatory obligations, system development and improvements, and onboarding and accreditation of the Merchant.

3.2. Legitimacy of Processing. By using EBANX’s Services, the Merchant represents and warrants that it has all necessary authorizations and/or legitimacy to share and/or allow EBANX to access/collect the Merchant Data. EBANX, in turn, represents and warrants that it will not sell, rent or license Merchant Data to any third parties. 

3.3. Common Obligations of the Parties. In relation to activities involving the Processing of Personal Data within the scope of the Agreement, the Parties undertake to:

a) Carry out any and all Processing of Personal Data in accordance with the Applicable Data Protection Laws, including those that come into force after the execution of this DPA;

b) Ensure that all Data Processing activities are duly justified and grounded under the Applicable Data Protection Laws;

c) Process only the Personal Data necessary for the performance of the Agreement, as well as to ensure compliance with legal or regulatory obligations to which the Parties are subject.   

3.4. Transparency. The Parties shall ensure that their privacy notices provide sufficient information to ensure due transparency to the Personal Data Subjects regarding the Processing carried out in the context of the Agreement. In this regard, the Merchant undertakes to inform the Data Subjects, in its privacy notice, that the Merchant Data may be shared with third parties, including payment service providers and business partners. Where required by the Applicable Data Protection Laws, the Merchant undertakes to expressly identify EBANX as its payment service provider.

3.5. Legal Bases and Consent. The Parties are individually responsible for identifying and substantiating the legal bases applicable to the Processing activities in which they act as Controllers. To the extent that consent is necessary for the Processing of Personal Data to comply with the Applicable Data Protection Laws, the Merchant shall be responsible for: (i) obtaining the necessary consents; (ii) storing evidence of their obtainment for the applicable statutory period; and (iii) providing such evidence to EBANX whenever reasonably requested. 

3..6. Children and Adolescents. If children and adolescents are part of the Merchant’s target audience, it shall be the Merchant’s responsibility, as applicable, to: (i) implement age verification mechanisms in accordance with market best practices and compatible with the scope of its products and/or services; (ii) process the Personal Data of minors in accordance with the Applicable Data Protection Laws, as well as with any and all regulations issued by competent authorities, including sector-specific regulations; and (iii) collect all authorizations necessary to carry out such Processing, including consent from legal guardians, where required.

3.6.1. If EBANX identifies indications that data of minors is being processed in breach of the Applicable Data Protection Laws, EBANX undertakes to notify the Merchant without undue delay, and may suspend the Processing of such Personal Data until it is duly regularized.

3.7 Data Protection Impact Assessment. If, under the Applicable Data Protection Laws, the Merchant is required to conduct a Data Protection Impact Assessment (“DPIA”) or equivalent document in connection with the Services provided by EBANX, EBANX shall cooperate and provide assistance, to the extent necessary and applicable, to provide the information required by the Merchant and enable the Merchant to comply with its obligations, provided that the Merchant is unable to obtain access to the relevant information by other means and to the extent that such information is available to EBANX.

3.8 Automation and Data Analysis Technologies. The Merchant acknowledges that EBANX may employ technologies and models for data analysis and automation, including statistical models, machine learning models and other technological solutions, in connection with the provision, support, security, maintenance and improvement of the Services. The use of these technologies includes fraud detection and prevention activities, optimization of payment routing and processing, risk scoring, transaction analysis, development and improvement of products, features and services, as well as other analytical, operational and security purposes related to the Services offered by EBANX. EBANX shall ensure that the use of such technologies and models complies with applicable laws and regulations, industry standards and this DPA, as applicable.   

3.8.1. EBANX shall not use Personal Data to develop, train or improve generative artificial intelligence models. For the purposes of this DPA, “generative artificial intelligence” means artificial intelligence systems specifically designed to generate new content, such as text, images, audio, video or other media, in response to prompts or based on patterns learned from training data. This restriction does not apply to machine learning used exclusively to support the performance or improvement of the Services provided by EBANX, such as fraud scoring, anomaly detection or routing optimization. 

4. Security Measures

4.1. The Parties shall maintain a documented information security and privacy program proportionate to the risks of the Processing, taking into account the nature of the data processed, as well as the scope, context and purposes of the Processing. Such program shall observe recognized standards appropriate to each Party’s activities, as well as the requirements set forth in Schedule  I, Security Measures. 

5. Employees of the parties

5.1. Restricted Access. The Parties shall ensure that the Processing of Personal Data carried out in the context of the Agreement is restricted to duly authorized Employees who need to access the Personal Data for purposes compatible with the Agreement and with their job duties, ensuring that such Employees: (i) receive appropriate training on privacy, data protection and information security; (ii) are aware of each Party’s obligations related to the Processing of Personal Data; and (iii) are subject to confidentiality agreements or professional or legal obligations of confidentiality and data protection.

5.2 Access Control. Each Party shall maintain technical and organizational access controls appropriate to the nature of the Personal Data processed in the context of the Agreement, including, where applicable, individual authentication, identity management, segregation of duties, periodic access review and timely revocation. Each Party shall maintain audit records, logs, relating to access to and activities performed in its systems and repositories that contain Personal Data. Such logs shall be protected against alteration and unauthorized access

6. Third-Party Contractors

6.1. The Parties may, within the limits of their activities, engage third parties to carry out part of the Processing of Personal Data related to the Agreement. In such engagements, such third parties shall be required to:

a) Process the Personal Data in accordance with the Applicable Data Protection Laws;

b) Preserve the integrity, accuracy, confidentiality and availability of the data processed, through the implementation of technical and administrative security measures capable of protecting the Personal Data against unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication or dissemination; 

c) Provide the necessary assistance to address requests from Personal Data Subjects, where applicable, including with respect to their duty to update, delete or anonymize such data, whether at the request of the contracting Party, where required by the Applicable Data Protection Laws, or upon request of the Data Subject, if the Personal Data does not need to be retained for another legitimate purpose, such as compliance with legal or regulatory obligations applicable to the third party.

6.2 Liability. The Parties shall be liable for the acts and omissions of third parties engaged to process Personal Data on their behalf.

6.3 Data Sharing with Third Parties. The Merchant acknowledges that EBANX may use its affiliates, third-party payment providers and business partners to perform, in whole or in part, its obligations and provide the contracted Services, including, but not limited to, acquirers, sub-acquirers, banks, tokenization partners and payment schemes/card networks. The Merchant further acknowledges that EBANX publicly makes available on its website a list of third parties with whom Personal Data may be shared, depending on the scope and territory of the contracted Services. Depending on the purpose of the sharing, such third parties may be classified as Controllers or Processors of the Personal Data.

7. International Data Transfers

7.1. The Parties acknowledge that, in the context of the Services, international transfers of Personal Data may occur, including, without limitation, transfers for cloud data storage purposes and disclosures to any third parties located outside the jurisdiction of the country where the Personal Data was collected. 

7.1.1 The Merchant undertakes to inform the Merchant Data Subjects of the possibility of international transfers of such data by its business partners and, where necessary and pursuant to the Applicable Data Protection Laws, to obtain the consents of such Data Subjects and provide them to EBANX upon reasonable request.

7.2. Server Location. The Merchant acknowledges and agrees that the primary data storage infrastructure used by EBANX is based in the United States of America. In addition, EBANX may use infrastructure located in other countries, as required by the Applicable Data Protection Laws and/or by sector-specific regulations. 

7.3. Transfer Mechanisms. The Parties shall ensure that any and all international transfers occur in accordance with the Applicable Data Protection Laws, whether by means of an adequacy decision issued by the Supervisory Authorities, through the standard contractual clauses, as set forth in Schedules A, B, C and D, or by any other legally permitted means, including the Data Subject’s consent.

8. Data Subject Rights

8.1. Individual Responsibility. Each Party shall be individually responsible for responding to requests from Data Subjects related to the Processing activities in which it acts as Controller. In this regard, EBANX shall respond directly to Data Subject requests relating to Processing carried out as an Independent Controller, and the Merchant shall respond to requests relating to Processing carried out as Controller of the relationship with the consumer. 

8.1.1. The Merchant acknowledges that EBANX publicly makes available the Privacy Portal, a dedicated environment for receiving and managing Data Subject requests in the jurisdictions where EBANX operates.

8.2. Cooperation between the Parties. The Parties undertake to cooperate with each other when responding to a Data Subject request depends on information or actions from the other Party. As a general rule, the Parties shall observe a period of five (5) business days from receipt of the cooperation request to provide the necessary response. If this period is not compatible with the deadlines established under the Applicable Data Protection Laws, the requesting Party shall indicate the expected response deadline in the cooperation communication, while undertaking to send such request within a reasonable period so that the other Party may comply with such request.

8.3. Execution of the Exercise of Rights by the Data Subject. The Parties, whenever reasonably requested, shall mutually cooperate in complying with obligations related to the exercise of rights by Data Subjects, in accordance with the Applicable Data Protection Laws, the scope of the Agreement and the terms of this DPA.

9. Security Incident

9.1. The Party that identifies the occurrence of a Security Incident in the context of its activities related to the Agreement shall, without undue delay, adopt the necessary measures to investigate the cause of such Incident, as well as to mitigate and remedy its consequences.

9.2. Notification between the Parties. If the Security Incident involves or may involve the Processing activities carried out by the other Party, the Party that identified the Incident shall, without undue delay and always in compliance with the specific deadlines under the Applicable Data Protection Laws, notify the other Party, providing sufficient information, to the extent then available, to allow the assessment of the Incident and the adoption of any necessary measures, pursuant to the Applicable Data Protection Laws and any specific sectoral regulations.

9.3. Cooperation between the Parties. To the extent of their respective activities, responsibilities, and available information, the Parties shall cooperate with each other, sharing, in a timely manner and whenever reasonably requested, relevant information in their possession regarding any Security Incidents, while preserving their trade secrets, industrial secrets, and confidentiality obligations to third parties.

9.4. Notification to Authorities and Data Subjects. Each Party is responsible, within the scope of its Processing operations related to the Security Incident, for complying with its legal obligations to notify the Supervisory Authorities and, where applicable, the Data Subjects. The Parties may coordinate the content and timing of any communications that jointly involve them, avoiding conflicting information and limiting disclosure to what is strictly necessary to comply with the Applicable Data Protection Laws and any regulations to which the Parties are subject.

9.5. Confidentiality of Information. The information exchanged between the Parties as a result of any Security Incident shall be treated as confidential. If, by virtue of their legal obligations, the Parties are required to disclose any information about a Security Incident involving the other Party, the Parties undertake to disclose only the information strictly necessary to comply with the Applicable Data Protection Laws.


10. Supervisory Authorities

10.1 Communication. The Parties shall inform each other, without undue delay, after receiving requests for information or orders from Supervisory Authorities related to any Processing activity carried out in the context of the Agreement, except where the request is subject to secrecy or any other type of legal restriction that prevents such communication.

10.2 Cooperation. The Parties undertake to cooperate mutually to comply with obligations or requests imposed by any competent Supervisory Authority, related to any Processing activities connected with the performance of the Agreement. As a general rule, the Parties shall observe a period of five (5) business days from receipt of the cooperation request to provide the necessary response. If this period is not compatible with the deadline imposed by the Supervisory Authority, the requesting Party shall indicate the expected response deadline in the cooperation communication, while undertaking to send such request within a reasonable period so that the other Party may comply with such request. 

10.3 Responsibility for Regulatory Interaction. Each Party shall be responsible for direct interaction with the Supervisory Authorities of its own jurisdiction or in relation to the Processing activities in which it acts as Controller. 

10.4 Mutual Assistance. The Parties undertake to provide the necessary assistance to each other, to the extent reasonably requested and taking into account the responsibilities and information available to each of them, to enable compliance with their obligations under the Applicable Data Protection Laws, as well as to respond to any request, inquiry or investigation by any competent Supervisory Authority regarding the Processing of Personal Data covered by the Agreement.

11. Deletion and Return of Personal Data

11.1 Upon termination of the provision of the Services, if requested by the Merchant or as appropriate, pursuant to the Applicable Data Protection Laws, EBANX shall securely delete and/or anonymize the Merchant Data that is no longer necessary for the provision of the Services or for compliance with legal and regulatory obligations by EBANX, or whose Processing can no longer be validly and legitimately justified under the Applicable Data Protection Laws.

12. Indemnification and Liability

12.1. Proportional Liability. Each Party shall be liable, to the extent and within the limits of its Processing activities, for its actions and omissions toward the other Party, the Data Subjects and the Supervisory Authorities, including any proven breach of the obligations set forth in this DPA and/or in the Applicable Data Protection Laws.

12.2. Shared Liability. If any sanctions, orders, claims, investigations, losses or expenses arise from Processing activities related to both Parties, each Party shall be liable to the extent of its responsibility and to the extent that such consequences were caused by its actions and/or omissions, negligence, recklessness, willful misconduct or other attributable and proven conduct. 

12.3. Administrative Sanctions. If a Supervisory Authority imposes sanctions on one of the Parties related to the Processing of Personal Data carried out in the context of the Agreement and the responsibility of the other Party is proven, such Party shall be exclusively responsible for the amount of the sanctions and/or penalties effectively imposed, to the exact extent of its proven responsibility, excluding any other costs, expenses or indirect damages.

12.4. Indemnification. All provisions on liability and indemnification set forth in the Agreement shall apply in full to the responsibilities assumed under this DPA, and the Agreement shall prevail in the event of conflict, including in the case of limitation of liability. There shall be no duplication of indemnification or liability for the same facts.


13 Certifications and Audit

13.1. Demonstration of Compliance. EBANX shall make available to the Merchant, whenever reasonably requested and no more than once per year, the information necessary to demonstrate compliance with its obligations under the Applicable Data Protection Laws and this DPA. Such information may be provided, at EBANX’s discretion, in the following forms: (i) internal or external audit reports; (ii) ISO/IEC compliance certificates; (iii) PCI-DSS compliance reports; (iv) reasoned responses to standardized security and privacy questionnaires. Such certifications and reports shall be accepted as primary evidence of compliance. An additional audit, pursuant to Clause 13.2 below, shall only be permitted if such evidence does not adequately cover the specific aspect questioned by the Merchant.

13.2 Additional Audits. If additional audit activities are deemed reasonably necessary - due to (i) an express requirement under the Applicable Data Protection Laws; (ii) a proven breach of this DPA; or (iii) a request from competent Supervisory Authorities -, the Merchant may request an additional audit to be carried out directly by the Merchant or by an auditor appointed by the Merchant, by mutual agreement with EBANX, from among audit firms of recognized market reputation.

13.3. Audit Procedure. Before the start of any additional audit, the Parties shall mutually agree on the start date, scope, schedule, duration and any reimbursable expenses. The costs of such additional audit shall be borne entirely by the Merchant. The audit shall relate solely to the Merchant’s Personal Data and may not extend to any other information of EBANX or of other EBANX clients. The Merchant shall promptly provide EBANX with information on any non-compliance discovered during the course of the additional audit, as well as use its best efforts to minimize interference with EBANX’s operations when conducting such audit. 

13.4. Objection to the Auditor. EBANX may, in good faith, submit a reasoned objection to the auditor appointed by the Merchant within ten (10) business days from receipt of the appointment, if it understands that the auditor is not adequately qualified or is a direct competitor of EBANX. If there is an objection, the Merchant shall appoint a new auditor within ten (10) business days. Regardless of whether the auditor appointed by the Merchant is a third-party contractor or not, such auditor shall sign a specific confidentiality agreement with EBANX before carrying out any activities. 

13.5. Confidentiality of Reports. Any reports or information arising from such additional audits shall be considered EBANX’s confidential information and may only be shared with third parties upon EBANX’s prior written authorization. 


14 - General Provisions

14.1. Jurisdiction and Governing Law. In the event of conflict between the provisions of this DPA and the Agreement or any other document executed between the Parties, specifically in connection with activities involving the Processing of Personal Data, the provisions of this DPA shall prevail, except where a provision of the DPA provides otherwise or a subsequent document is executed between the Parties expressly declaring the subsidiary nature of this DPA. 

14.2. Order of Precedence. No caso de conflito entre as disposições deste DPA e o Contrato ou qualquer outro documento executado entre as partes, especificamente em conexão com atividades que envolvam o Tratamento de Dados Pessoais, as disposições deste DPA prevalecerão, exceto quando uma disposição do DPA estabeleça o contrário ou documento superveniente for executado entre as Partes, declarando expressamente a natureza subsidiária deste DPA.

14.3. Amendments. This DPA may be amended, including in the event of any subsequent law, regulation or order from any competent Supervisory Authority requiring the amendment of its provisions. The Parties undertake to negotiate amendments in good faith, without the need for full renegotiation of the DPA, unless there is a significant impact on the obligations assumed by either Party.

14.4. Severability. If any provision of this DPA is deemed null, invalid or unenforceable, the remaining provisions shall remain in full force and effect. The null, invalid or unenforceable provision shall be amended by the Parties to ensure its validity and effectiveness, while preserving the original intent.

14.5. Term. This DPA shall enter into force and terminate together with the Agreement. EBANX undertakes to act in accordance with the Applicable Data Protection Laws even after termination of the Agreement to the extent that EBANX continues to process the Merchant’s Personal Data, pursuant to Clause 11. 

14.6 Headings. The headings and subheadings used in the clauses and sections of this DPA are for organizational and reference purposes only and do not form an integral part of the normative content of the instrument. The headings shall not be used for purposes of interpreting or limiting the scope of the provisions to which they refer, nor to restrict or expand the meaning of the corresponding clauses. In the event of any discrepancy between the heading of a clause and its content, the text of the clause shall fully prevail. 

Schedule I - Security Measures

1. Information Security Program

The Parties agree to implement and maintain a comprehensive and documented Information Security Program (“Information Security Program”), including administrative, technical and organizational measures, practices and documented policies, in accordance with commercially reasonable standards currently in force in the industry, for the purpose of protecting the Merchant’s Confidential Information, including personal data, critical business processes, confidential intellectual property, trade secrets, IT assets, third-party confidential information and other sensitive or proprietary information (“Merchant’s Confidential Information”). The Information Security Program shall comply with all applicable laws and regulations, the Agreement, the DPA and this Schedule.

1.1. Security Policies

The Parties shall maintain documented policies or standards appropriate for maintaining their Information Security Program.

The Merchant acknowledges that EBANX publicly makes available its Information Security Policy through the following link: https://www.ebanx.com/en/legal/ebankers/terms-and-conditions/information-security-policy/.

1.2. Security Training and Awareness

The Parties shall train their Employees at least annually on the Information Security Program. The training shall cover, at a minimum:

•   instructions on the collection, use, sharing, retention, destruction and inappropriate or prohibited uses of the Merchant’s Confidential Information;

•   security policies, including acceptable use, password protection, data classification, incident reporting and consequences of violations;

•   common attack mechanisms and how to identify them;

•   security practices for remote work and travel; and

•    an overview of applicable laws and regulations, including privacy and data protection.

1.3. Personnel Security

The Parties are responsible for conducting reasonable background checks on their Employees, consistent with local industry practices and in accordance with applicable laws. 


2. Access Control and Credential Management

Each Party shall implement and maintain credential management for Employees with access to systems, applications or repositories containing Personal Data, observing the following guidelines:

2.1. Conditions for Granting Access

Access to systems containing the Merchant’s Confidential Information may only be granted when:

•   the access is necessary for the performance of the Services and limited to what is strictly necessary for the performance of job duties (principle of least privilege);

•   the Employee has been trained in the proper handling of Confidential Information in accordance with the Information Security Program;

•   the access can be uniquely identified through a unique and individual user identifier (User ID);

•   the Employee uses a password or other authentication token configured in accordance with the industry’s minimum security standards;

•   the date, time, requester and nature of the access, read or modification, are recorded in a log file maintained and preserved in accordance with applicable laws and industry standards.

2.2. Credential Requirements

Credentials shall be:

•   individual and not shared among Employees;

•   protected by minimum security policies, including, where feasible, multi-factor authentication (MFA);

•   changed periodically in a manner proportionate to the associated risk and immediately whenever compromise is suspected;

•   changed before first use, in the case of default credentials.

2.3. Access Lifecycle

The access lifecycle shall be strictly managed so that:

•   access is granted based on the principle of least privilege and reviewed periodically;

•   inactive accounts are disabled within a reasonable period;

•   unsuccessful access attempts result in automatic account lockout; and

• in the event of termination of employment, contractual termination or change of role that makes access unnecessary, the credentials and corresponding access are immediately deactivated.


3. Technical, Administrative and Organizational Measures

The technical, administrative and organizational measures implemented shall include, as appropriate and proportionate to the risk:

3.1. Encryption

EBANX shall adopt commercially reasonable and current encryption techniques, including:

•   encryption of Personal Data in transit, using secure protocols and encryption standards recognized by the industry;

•   encryption of Personal Data at rest, where technically feasible, through transparent encryption techniques.

3.2. Network Security

EBANX shall maintain:

•   network perimeter defense solutions, including Intrusion Detection Systems (IDS)/Intrusion Prevention Systems (IPS) and firewalls;

•   network segmentation to isolate environments containing Personal Data;

•   storage of the Merchant’s Confidential Information protected by firewalls, with access restricted as provided in this Schedule; and

•    periodic review of firewall configurations and rules, at least annually.

3.3. Log Recording and Monitoring

EBANX shall maintain records (logs) of:

•   user logins and logouts in the systems;

•   read, write and deletion operations on application and system objects and users;

•   changes to security settings (including disabling log recording);

•   access by application owners to customer data (access transparency).

The logs shall include: user identifier, IP address, valid timestamp, type of action performed and object of the action. Logs shall be stored for at least thirty (30) days and shall not contain sensitive data or payloads.

3.4. Vulnerability Management and Patching

EBANX shall:

•   perform network vulnerability scans at least monthly and after any change to the network configuration;

•   promptly apply high or critical severity security fixes (patches) to production servers, endpoints and endpoint management systems; and 

•  promptly install any security patches identified by hardware or software manufacturers.

3.5. Backups, Business Continuity and Disaster Recovery

EBANX shall perform backups of the Merchant’s Confidential Information in secure facilities, with environmental controls and restricted access, where permitted or required by the Agreement and/or the DPA. EBANX shall maintain appropriate business continuity and disaster recovery plans to ensure the availability and integrity of the Personal Data processed.

3.6. Change Management

EBANX shall follow documented change management policies and procedures for requesting, testing and approving changes to applications, infrastructure and products. Changes shall be subject to review and testing before approval for implementation. The promotion to production of any approved code shall be carried out exclusively by authorized Employees. EBANX shall maintain separate environments for development, testing and production.

3.7. Cryptographic Key Management

EBANX shall maintain cryptographic key management procedures that include:

•   secure generation, distribution, activation, storage, recovery and replacement/update of cryptographic keys;

•   regular key rotation; and

•    immediate revocation or deactivation of lost, corrupted or expired keys.

3.8. PCI DSS Compliance

To the extent that EBANX transmits or processes payment card information on behalf of the Merchant, EBANX shall comply with applicable industry security standards, including, without limitation, PCI DSS standards, and shall provide the Merchant with evidence of such compliance upon request.


4. Periodic Testing, Assessments and Verifications

The Parties shall conduct periodic testing, assessments and verifications of the effectiveness of the technical, administrative and organizational measures adopted, for the purpose of ensuring the security of the operations involving the Processing of Personal Data.

4.1. Internal Controls Testing

EBANX shall conduct regular testing of the controls, systems and procedures of its Information Security Program in order to ensure that they are properly implemented and effective in addressing the identified threats and risks. The testing shall be conducted or reviewed by independent third parties or by a team independent from the team that develops or maintains the Information Security Program.

4.2. Penetration Testing

EBANX shall conduct penetration testing at least annually, including:

•   internal network penetration testing;

•   external web application penetration testing; and

•   mobile application penetration testing.

EBANX shall provide the Merchant with the test results and the respective remediations upon request.


5. Audits, Assessments and Remediation

5.1. Compliance Records

EBANX shall maintain records to demonstrate compliance with this Schedule and with the applicable data laws and regulations, providing such records to the Merchant upon request.

5.2. Certifications

For purposes of verifying compliance with applicable laws and regulations, EBANX shall provide the Merchant, upon request, with the PCI-DSS, ISO/IEC 27701:2019, ISO/IEC 27018:2019 and ISO/IEC 27001:2022 compliance certificates.

5.3. Remediation

EBANX shall take immediate measures to correct any demonstrable security issue affecting the Merchant’s Confidential Information, even if such issue does not reach the level of a Security Incident, and shall inform the Merchant of the actions taken within a reasonable period after discovery.

5.4. Secure Disposal

The Merchant’s Confidential Information, in any format contained in printed materials, hardware and/or electronic media and any storage media, shall be securely deleted and/or anonymized: (i) during the term of the Agreement, upon the Merchant’s written request, when such information is no longer reasonably necessary for the provision of the Services; or (ii) upon termination or expiration of the Agreement, unless its retention is required for EBANX to comply with its legal and regulatory obligations.

5.5. Update of Requirements

EBANX agrees to implement and maintain the necessary changes provided for in this Schedule in accordance with the applicable laws and regulations in force. 

SCHEDULE A: LATAM TERMS

This Schedule A forms an integral part of the Data Processing Agreement (“DPA”) entered into between EBANX and the Merchant and establishes specific requirements for the Processing of Personal Data of Data Subjects located in the countries of South America, Central America and Mexico, as identified in Section 1 below. In the event of conflict between this Schedule A and the DPA, the provisions of this Schedule A shall prevail with respect to the Processing activities conducted in the jurisdictions covered herein.


1. TERRITORY AND APPLICABLE LAWS

1.1. The provisions of this Schedule A cover the Services provided by EBANX in the following countries and their respective personal data protection laws: 

1.2. The Parties undertake to monitor legislative developments, proactively incorporate into their activities any secondary regulations as they are published by competent Supervisory Authorities, and update their Personal Data Processing practices as necessary, making the appropriate amendments to this Schedule A in good faith, without the need to renegotiate the DPA, unless there is a material impact on the obligations of either Party. 


  • Argentina - Act No. 25,326 of 2000

  • Brazil - Law No. 13,709/2018 (LGPD)

  • Chile - Law No. 21,719

  • Colombia - Law No. 1,581/2012

  • Costa Rica - Law No. 8,968/2011

  • Ecuador - Organic Law on the Protection of Personal Data (LOPDP)

  • Mexico - Federal Law for the Protection of Personal Data in Possession of Private Parties (LFPDPPP)

  • Panama - Law No. 81/2019

  • Paraguay - Law No. 6,534/2020

  • Peru - Law No. 29,733/2011

  • Dominican Republic - Law No. 172-13

  • Uruguay - Law No. 18,331/2008


2. DEFINITIONS

2.1. The following terms shall have the meanings assigned to them by the Applicable Data Protection Law in each jurisdiction: “Controller” (or equivalent - “Data Controller”, “Processing Responsible”, “Responsable”), “Processor” (or equivalent - “Encargado”, “Operador”), “Data Protection Officer” (or equivalent - “Encarregado”, “Delegado de Protección de Datos”), “Personal Data”; “Sensitive Personal Data”; “Processing”; and “International Data Transfer”. 

2.2. If any of the terms indicated above does not nominally exist in the Applicable Data Protection Law, the Parties shall interpret them considering the intent intended by the legislator with such definitions. 


3. LEGAL BASES  

3.1. The Parties shall ensure that each Personal Data Processing activity is supported by a valid legal basis under the Applicable Data Protection Laws. The predominant legal bases in the context of the Services include:

  • Performance of a contract: Processing necessary for the provision of the Services and fulfillment of contractual obligations with the Data Subject. 

  • Compliance with a legal or regulatory obligation: Processing necessary to meet requirements imposed by law, including obligations of the Central Bank, payment regulators and other competent authorities. 

  • Legitimate interest: In jurisdictions that allow this legal basis, the Parties may process Personal Data based on legitimate interest, provided that the applicable legal safeguards are observed. 

  • Consent: Where consent is the applicable or required legal basis, the Merchant is responsible for collecting, recording and managing consents, including any presentation thereof to Supervisory Authorities, under the terms established in the DPA.


4. INTERNATIONAL TRANSFERS

4.1. Where there is no adequacy decision issued by the Supervisory Authorities, the Parties agree that international transfers shall preferably be supported by the standard contractual clauses applicable to each country or, alternatively, by another mechanism approved by the competent Supervisory Authorities.

4.2. Where international transfers are supported by specific contractual clauses, the Parties shall carry them out in compliance with the following mechanisms: 

4.2.1. Brazil: Standard Contractual Clauses approved by the Agência Nacional de Proteção de Dados through Resolution CD/ANPD No. 19/2024, (“Standard Contractual Clauses”) and incorporated herein by reference, according to the following parameters:

a) Clause 1 of the Standard Contractual Clauses will be set as follows:b) Clause 2 of the Standard Contractual Clauses will be set as follows:

  • Exporter (Merchant):

Name: As provided in the preamble of the Agreement.

Qualification: As provided in the preamble of the Agreement.

Main Address: As provided in the preamble of the Agreement.

E-mail Address: As provided in the Agreement.

Contact for the Data Subject: As provided in the Agreement.

Other information: N/A

Role: Exporter/Controller

  • Importer (EBANX):

Name: EBANX

Qualification: As provided in the preamble of the Agreement.

Main Address: As provided in the preamble of the Agreement.

E-mail Address: privacy@ebanx.com

Contact for the Data Subject: EBANX's Privacy Portal and privacy@ebanx.com

Other information: N/A

Role: Importer/Controller


b) Clause 2 of the Standard Contractual Clauses will be set as follows:

  • Main purposes of the transfer: Enable the delivery of the services provided for on the Agreement, including payment processing, chargeback management, refunds, and financial reconciliation.

  • Categories of personal data transferred: Identification Personal Data (name, phone number, email address, IP address and device identifier, government identification number, and purchase information). Additional data may be transferred in accordance with the applicable laws and regulations and the Parties' Privacy Notice.

  • Period of data storage: During the term of the Agreement.

  • Other information: N/A


c) Option B will be applied to Clause 3.1 of the Standard Contractual Clauses, as follow

  • Main purposes of the transfer: Enable the delivery of the services provided for on the Agreement, including payment processing, chargeback management, refunds, and financial reconciliation.

  • Categories of personal data transferred: Identification Personal Data (name, phone number, email address, IP address and device identifier, government identification number, and purchase information). Additional data may be transferred in accordance with the applicable laws and regulations and the Parties' Privacy Notice.

  • Period of data storage: During the term of the Agreement.

  • Other information: N/A


d) Option A will be applied to Clause 4.1 of the Standard Contractual Clauses, being that the Exporter will be responsible for compliance with the obligations set on items “a”, “b” and “c”, without prejudice to the respective contractual responsibilities of each Party in the terms of the Agreement;

e) the technical and organizational measures set in the Agreement will replace the table included in Section III of the Standard Contractual Clauses; and

f) Section IV of the Standard Contractual Clauses will remain blank.


4.2.2. Other Countries - Members of the Ibero-American Data Protection Network (“RIPD”): the Parties shall adopt the RIPD Model Contractual Clauses, in accordance with the parameters set forth below, or, alternatively, may opt for the standard contractual clauses specific to a given jurisdiction.

a) SCHEDULE A: Accession Forms for New Partners

Not applicable

b) SCHEDULE B: Description of the Transfer

Categories of Data Subjects whose Personal Data is transferred: End users of the Merchant’s services

Sensitive Personal Data transferred, if applicable, and restrictions or safeguards applied: Not applicable to the standard scope of the Services.

Frequency of Transfer: Continuous, during the term of the Agreement

Purpose(s) of the transfer and subsequent Data Processing: Payment processing, chargeback management, refunds, and financial reconciliation.

c) SCHEDULE C: Administrative, Physical and Technical Measures to Ensure Data Security in accordance with EBANX’s Information Security Policy, available at  (https://www.ebanx.com/en/legal/ebankers/terms-and-conditions/information-security-policy/), PCI-DSS, ISO/IEC 27001, 27701 and 27018, and Schedule I to the DPA. 

SCHEDULE B: AMET TERMS

This Schedule B forms an integral part of the Data Processing Agreement (“DPA”) entered into between EBANX and the Merchant and establishes specific requirements for the Processing of Personal Data of Data Subjects located in the countries of Africa, the Middle East and Turkey, as identified in Section 1 below. In the event of conflict between this Schedule B and the DPA, the provisions of this Schedule B shall prevail with respect to the Processing activities conducted in the jurisdictions covered herein.


1. TERRITORY AND APPLICABLE LAWS 

1.1. The specific provisions of this Schedule B cover the Services provided by EBANX in the following countries and their respective personal data protection laws: 


  • South Africa - Protection of Personal Information Act 4/2013 (POPIA)

  • Egypt - Resolutions No. 151/2020 and No. 816/2025

  • Nigeria - Nigeria Data Protection Act 2023 (NDPA)

  • Kenya - Data Protection Act 2019

  • Turkey - Law on Protection of Personal Data No. 6,698/2016


1.2. The Parties undertake to monitor legislative developments, proactively incorporate into their activities any secondary regulations as they are published by competent Supervisory Authorities, and update their Personal Data Processing practices as necessary, making the appropriate amendments to this Schedule B in good faith, without the need to renegotiate the DPA, unless there is a material impact on the obligations of either Party.


2. DEFINITIONS

2.1. The following terms shall have the meanings assigned to them by the Applicable Data Protection Law in each jurisdiction: “Controller” (or equivalent), “Processor” (or equivalent), “Data Protection Officer” (or equivalent - “Responsible for Processing”), “Personal Data”, “Sensitive Personal Data”, “Processing” and “International Data Transfer”. 

2.2. If any of the terms indicated above does not nominally exist in the Applicable Data Protection Law, the Parties shall interpret them considering the intent intended by the legislator with such definitions.


3. LEGAL BASES 

3.1. The Parties shall ensure that each Personal Data Processing activity is supported by a valid legal basis under the Applicable Data Protection Laws. The predominant legal bases in the context of the Services include:

  • Performance of a contract: Processing necessary for the provision of the Services and fulfillment of contractual obligations with the Data Subject. 

  • Compliance with a legal or regulatory obligation: Processing necessary to meet requirements imposed by law, including obligations of the Central Bank, payment regulators and other competent authorities. 

  • Legitimate interest: In jurisdictions that allow this legal basis, the Parties may process Personal Data based on legitimate interest, provided that the applicable legal safeguards are observed. 

  • Consent: Where consent is the applicable or required legal basis, the Merchant is responsible for collecting, recording and managing consents, including any presentation thereof to Supervisory Authorities, under the terms established in the DPA.


4. INTERNATIONAL TRANSFERS 

4.1. Where there is no adequacy decision issued by the Supervisory Authorities, the Parties agree that international transfers shall preferably be supported by the standard contractual clauses applicable to each country or, alternatively, by another mechanism approved by the competent Supervisory Authorities.

4.2. Where international transfers are supported by specific contractual clauses, the Parties shall carry them out in compliance with the following mechanisms: 

4.2.1. Turkey: Standard contractual clauses adopted by the Personal Data Protection Board through Decision No. 2024/959.

4.2.2. Other countries: Implementation of contractual measures that ensure a level of protection equivalent to that required by the Applicable Data Protection Law, where permitted. In the absence of a specific formal mechanism approved by the local Supervisory Authority, the Parties shall adopt the EU SCCs as a reference for contractual best practices, supplemented by Schedule II to this DPA.

SCHEDULE C: APAC TERMS

This Schedule C forms an integral part of the Data Processing Agreement (“DPA”) entered into between EBANX and the Merchant and establishes specific requirements for the Processing of Personal Data of Data Subjects located in the countries of Asia and the Asian Pacific, as identified in Section 1 below. In the event of conflict between this Schedule C and the DPA, the provisions of this Schedule C shall prevail with respect to the Processing activities conducted in the jurisdictions covered herein.


1. TERRITORY AND APPLICABLE LAWS 

1.1. The specific provisions of this Schedule C cover the Services provided by EBANX in the following countries and their respective personal data protection laws:


  • Philippines - Data Privacy Act 2012 (Republic Act No. 10,173)

  • India - Digital Personal Data Protection Act 2023 and Digital Data Protection Rules 2025

  • Indonesia - Personal Data Protection Law 2022

  • Malaysia - Personal Data Protection Act 2010 (PDPA)

  • Thailand - Personal Data Protection Act 2019 (PDPA)

  • Vietnam - Personal Data Protection Law (PDPL)


1.2. The Parties undertake to monitor legislative developments, proactively incorporate into their activities any secondary regulations as they are published by competent Supervisory Authorities, and update their Personal Data Processing practices as necessary, making the appropriate amendments to this Schedule C in good faith, without the need to renegotiate the DPA, unless there is a material impact on the obligations of either Party. 


2. DEFINITIONS 

2.1. The following terms shall have the meanings assigned to them by the Applicable Data Protection Law in each jurisdiction: “Controller” (or equivalent), “Processor” (or equivalent), “Data Protection Officer” (or equivalent - “Responsible for Processing”), “Personal Data”, “Sensitive Personal Data”, “Processing” and “International Data Transfer”.

2.2. If any of the terms indicated above does not nominally exist in the Applicable Data Protection Law, the Parties shall interpret them considering the intent intended by the legislator with such definitions. 


3. LEGAL BASES  

3.1. The Parties shall ensure that each Personal Data Processing activity is supported by a valid legal basis under the Applicable Data Protection Laws. The predominant legal bases in the context of the Services include: 

  • Performance of a contract: Processing necessary for the provision of the Services and fulfillment of contractual obligations with the Data Subject. 

  • Compliance with a legal or regulatory obligation: Processing necessary to meet requirements imposed by law, including obligations of the Central Bank, payment regulators and other competent authorities. 

  • Legitimate interest: In jurisdictions that allow this legal basis, the Parties may process Personal Data based on legitimate interest, provided that the applicable legal safeguards are observed.. 

  • Consent: Where consent is the applicable or required legal basis, the Merchant is responsible for collecting, recording and managing consents, including any presentation thereof to Supervisory Authorities, under the terms established in the DPA.


4. INTERNATIONAL TRANSFERS

4.1. Where there is no adequacy decision issued by the Supervisory Authorities, the Parties agree that international transfers shall preferably be supported by the standard contractual clauses applicable to each country or, alternatively, by another mechanism approved by the competent Supervisory Authorities.

4.2. Where international transfers are supported by specific contractual clauses, the Parties shall carry them out in compliance with the following mechanisms: 

4.2.1. Thailand: Standard contractual clauses recognized by the Personal Data Protection Committee (“PDPC”), including the Thai Model, the International Model, the model contractual clauses of the Association of Southeast Asian Nations (“ASEAN”) and the standard contractual clauses of the European Union. 

4.2.2. Other countries: Implementation of contractual measures that ensure a level of protection equivalent to that required by the Applicable Data Protection Law, where permitted. In the absence of a specific formal mechanism approved by the local Supervisory Authority, the Parties shall adopt the EU SCCs as a reference for contractual best practices, supplemented by Schedule II to this DPA.

SCHEDULE D: EUROPEAN REGION TERMS

1. TERRITORY:

The specific provisions of this Schedule D cover the Services provided by EBANX in the following countries: 

  • European Economic Area (EEA)

  • United Kingdom

  • Switzerland


2. DEFINITIONS:

In addition to the terms defined in the DPA, the following definitions apply to these European Region Terms:

2.1. The terms “Controller”, “Data Subject”, “Processor”, “Supervisory Authority”, “Personal Data” and “Processing” shall have the meanings set forth in the GDPR or the UK GDPR, as applicable.

2.2. “Approved Purpose” means the purpose(s) for which EBANX may process the Merchant Data, as expressly specified in the Agreement.

2.3. “Standard Contractual Clauses” (“SCCs”) means the European Commission’s standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, as set forth in the annex to Commission Implementing Decision 2021/914, which, as of the Last Updated date, are available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj and are incorporated herein by reference.

2.4. “UK Addendum” means the International Data Transfer Addendum of the UK Information Commissioner’s Office to the SCCs, which, as of the Last Updated date, is available at https://ico.org.uk/media/for-organisations/documents/4019483/international-data-transfer-addendum.pdf and is incorporated herein by reference.

3. CONTROLLER TERMS

3.1. The Merchant and EBANX shall act as independent Controllers in accordance with the scope of the Agreement, and Personal Data shall be exchanged between the Merchant and EBANX, applying the European Data Protection Requirements. The Parties agree as follows:

3.2. If Personal Data is exchanged between the Merchant and EBANX in connection with the Agreement or the provision of the Services:

a) To the fullest extent permitted by the applicable European Data Protection Requirements, the Parties shall each be independent controllers of the Personal Data and, as such, shall independently determine the purposes and means of Processing such Personal Data;

b) Each Party shall be individually responsible for ensuring that its Processing of Personal Data is lawful, fair and transparent in accordance with the applicable European Data Protection Requirements, including, where applicable, based on the Data Subject’s unambiguous consent, or based on another valid legal basis provided for under the applicable European Data Protection Requirements; and

c) Each Party shall implement and maintain appropriate technical and organizational measures to protect any Personal Data in its possession or control against: (i) accidental or unlawful destruction; and (ii) loss, alteration, or unauthorized disclosure or access, and that provide a level of security appropriate to the risk represented by any Processing and to the nature of the Personal Data to be protected.


4. INTERNATIONAL TRANSFERS

4.1. If Personal Data is transferred by the Merchant to EBANX in connection with the Agreement and EBANX is located outside the European Economic Area (“EEA”), such transfer shall be governed by the SCCs. For the avoidance of doubt, the following clauses or the UK Addendum shall not apply to the extent that the Personal Data is transferred to a country or territory that, at the time of such transfer, is deemed to ensure an adequate level of protection by the European Commission or by the UK Information Commissioner’s Office.

4.2. For the purposes of the EU SCCs, the following shall apply:

a) Module One (Controller to Controller) shall apply.

b) Clause 11: The optional clause allowing Data Subjects to lodge a complaint with an independent dispute resolution body is removed.

c) Clause 17: As defined in the Agreement.

d) Clause 18: The EU Member State in which any dispute arising from these Clauses shall be resolved shall be the courts of the jurisdiction stipulated in the Agreement. 

4.3. For the purposes of Annex I to the SCCs:

a) LIST OF PARTIES

  • Data Exporter(s):

Name: Merchant and its Affiliates, as defined in the Agreement.

Address: As defined in the Agreement

Contact person’s name: As defined in the Agreement.

Activities relevant to the data transferred under these Clauses: All Personal Data Processing activities agreed in the Agreement.

Signature and date: Signed and dated by and on behalf of the data exporter by execution of the Agreement.

Role: Controller.

  • Data Importer(s):

Name: EBANX and its Affiliates, as defined in the Agreement.

Address: As defined in the Agreement.

Contact person’s name: Giovanna Michelato, Data Protection Officer, privacy@ebanx.com

Activities relevant to the data transferred under these Clauses: All Personal Data Processing activities agreed in the Agreement.

Signature and date: Signed and dated by and on behalf of the data exporter by execution of the Agreement.

Role: Controller.

b) DESCRIPTION OF THE TRANSFER

Categories of data subjects whose personal data is transferred: Merchant’s customers.

Categories of personal data transferred: Identification Personal Data, such as name, phone number, email address, IP address and device identifier, government identification number, and purchase information. Additional data may be transferred in accordance with the regulations and the Parties’ Privacy Notice.

Sensitive data transferred: Not applicable.

Frequency of the transfer: The data transfer is continuous throughout the provision of the services.

Nature and purpose of the processing: EBANX’s activity is as described in the Services under the Agreement. These responsibilities are focused on facilitating the processing of the Merchant’s payments. This includes receiving payment information from the Merchant’s customers, verifying its accuracy and integrity, obtaining payment authorization and settling the authorized funds directly with the Merchants.

The period for which the Personal Data will be retained or, if this is not possible, the criteria used to determine that period: EBANX shall process Personal Data during the term of the Agreement and as required by Applicable Law, and not thereafter, unless the Merchant explicitly instructs EBANX to do so.

c) SUPERVISORY AUTHORITY

Identify the competent supervisory authority or authorities in accordance with Clause 13: As defined in the Agreement.

4.4. Without prejudice to the provisions set forth in Sections 4.2 to 4.6 of these European Region Terms, nothing in the Agreement or in this DPA, including these European Region Terms, is intended to vary or modify the SCCs. The Merchant and EBANX agree that Section I, optional Clause 7, and the optional paragraph in Section II, Clause 11 of the SCCs shall not apply.

4.5. For the purposes of the UK Addendum, as permitted by Clause 17 of such addendum, the parties agree to amend the format of the information set forth in Part 1 of the addendum so that:

a) the details of the parties in Table 1 shall be as set forth above, with no signature required;

b) for the purposes of Table 2, the addendum shall be attached to the EU SCCs, including the module selection and the application/non-application of such optional clauses as specified above; and

c) the appendix information listed in Table 3 shall be as set forth above.

4.6. If the SCCs or the UK Addendum are (i) deemed invalid by the European Commission, the UK Information Commissioner’s Office, a relevant regulator or supervisory authority for any reason, or (ii) replaced by other standard contractual clauses issued or approved by the European Commission, the UK Information Commissioner’s Office, a relevant regulator or supervisory authority, the Merchant and EBANX shall immediately comply with such other standard contractual clauses or any other valid mechanism under the European Data Protection Requirements to transfer and process personal data outside the EEA and/or the United Kingdom, as applicable.


Privacy Documents

Public