Paysell
РешенияТарифыДокументацияБлог
ВойтиСоздать аккаунт
Соглашения

Data Processing Agreement

Terms under which Paysell processes personal data on behalf of the merchant, including sub-processors, security measures, transfers and assistance duties.

Обновлено
6 сент. 2026 г.
Содержание
  • 1. Parties, scope and roles
  • 2. Subject matter and details of processing
  • 3. Obligations of the Merchant as controller
  • 4. Obligations of Paysell as processor
  • 5. Security measures
  • 6. Sub-processors
  • 7. International transfers
  • 8. Personal data breaches
  • 9. Audits
  • 10. Deletion and return
  • 11. Liability and term
  • 12. Governing law
  • Contact
Содержание
  • 1. Parties, scope and roles
  • 2. Subject matter and details of processing
  • 3. Obligations of the Merchant as controller
  • 4. Obligations of Paysell as processor
  • 5. Security measures
  • 6. Sub-processors
  • 7. International transfers
  • 8. Personal data breaches
  • 9. Audits
  • 10. Deletion and return
  • 11. Liability and term
  • 12. Governing law
  • Contact

Version 1.0 · Effective [[Effective date]] · Last updated [[Effective date]]

In short: When Paysell processes personal data on your behalf — mainly the data your Integration sends with an invoice and the payment data attached to it — Paysell acts as your processor and you act as the controller. This agreement sets out what Paysell may do with that data, the security it applies, the sub-processors it uses, and what happens when the relationship ends. For data Paysell processes about you as a merchant, Paysell is the controller and the Privacy Policy applies instead.

1. Parties, scope and roles#

1.1 This Data Processing Agreement ("DPA") is entered into between [[Company legal name]], registration number [[Registration number]], registered at [[Registered address]] ("Paysell", the processor), and the merchant identified in the Account ("Merchant", "you", the controller).

1.2 The DPA forms part of and is incorporated into the Terms of Service. It applies where and to the extent that Paysell processes personal data on your behalf in connection with the Services, and to the extent that data protection law applicable to you — such as the EU General Data Protection Regulation, the UK GDPR, or an equivalent law in [[Jurisdiction]] — imposes an obligation to conclude such an agreement.

1.3 Where Paysell is a controller, not a processor. Paysell is an independent controller of the personal data of Account holders and cabinet users (registration data, authentication data, session records, support tickets, audit logs), and of data it processes to meet its own legal, security and anti-money-laundering obligations. Those activities are governed by the Privacy Policy and not by this DPA.

1.4 If any term of this DPA conflicts with the Terms of Service on the subject of personal data processed on your behalf, this DPA prevails.

2. Subject matter and details of processing#

ItemDetail
Subject matterProcessing of personal data necessary for Paysell to accept crypto-asset payments and execute payouts for the Merchant's Shops
DurationFor the term of the Terms of Service, plus any retention period required by law
Nature and purposeCreating and monitoring invoices; matching blockchain transactions to invoices; crediting balances; sending webhooks; fraud, security and compliance checks carried out on your instruction
Types of personal dataOrder and invoice identifiers and any customer reference, description or metadata that the Merchant chooses to send through the API; buyer wallet addresses and on-chain transaction data associated with an invoice; any personal data the Merchant includes in a support ticket
Categories of data subjectsThe Merchant's buyers and customers; the Merchant's own staff whose details appear in submitted content
Special categoriesNone requested or required. The Merchant must not send special-category data, government identifiers or payment card data through the API or in invoice metadata

Note for the Merchant: you control what goes into invoice metadata. Send the minimum you need. Do not put names, e-mail addresses, postal addresses, dates of birth or free-text customer details in invoice fields where an internal order identifier would do.

3. Obligations of the Merchant as controller#

3.1 You warrant that you have a valid legal basis for the processing you instruct, that you have given your data subjects the information required by applicable law, and that your instructions do not cause Paysell to breach that law.

3.2 You are responsible for the accuracy and lawfulness of the personal data you transmit, and for the security of your own systems, credentials and webhook endpoints.

3.3 You must not instruct Paysell to process data for a purpose unrelated to the Services.

4. Obligations of Paysell as processor#

Paysell will:

4.1 process personal data only on your documented instructions, which consist of this DPA, the Terms of Service, the configuration of your Shops and your use of the API — unless required to process by a law to which Paysell is subject, in which case Paysell will inform you unless that law forbids it;

4.2 ensure that persons authorized to process the data are bound by confidentiality obligations and receive access on a need-to-know basis only, according to their role in the cabinet (client, support, manager, admin);

4.3 implement and maintain the technical and organizational measures described in clause 5;

4.4 not engage a sub-processor except as set out in clause 6;

4.5 taking into account the nature of the processing, assist you by appropriate measures, so far as reasonably possible, in responding to requests from data subjects exercising their rights;

4.6 assist you in ensuring compliance with your obligations relating to security of processing, notification of personal data breaches, data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to Paysell;

4.7 at your choice, delete or return the personal data at the end of the provision of the Services, subject to clause 8;

4.8 make available to you the information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as set out in clause 9;

4.9 inform you if, in its opinion, an instruction infringes applicable data protection law.

5. Security measures#

5.1 Paysell maintains measures appropriate to the risk, which currently include:

  • transport encryption (HTTPS/TLS) for the website, the cabinet and the API;
  • encryption at rest of user e-mail addresses; passwords stored only as Argon2 hashes;
  • optional TOTP two-factor authentication with recovery codes for Account holders, and reviewable, revocable login sessions;
  • per-Shop API keys shown once and revocable at any time, and webhook payloads signed with HMAC-SHA256 with a ±300-second replay window;
  • role-based access control in the cabinet (client, support, manager, admin) and an audit log of administrative actions;
  • manual operator review of every withdrawal before funds leave Paysell-controlled wallets;
  • separation of production credentials from development environments, and restricted administrative access to servers.

5.2 Paysell may change these measures, provided the level of security is not reduced. A current description is available on request and in the Security and Responsible Disclosure policy.

5.3 Blockchain data — addresses, amounts, transaction hashes and timestamps — is public by design and cannot be encrypted, restricted, corrected or erased by Paysell once it is on the network. This is a limitation of the technology and applies to any crypto payment service.

6. Sub-processors#

6.1 You give Paysell general authorization to engage sub-processors for the provision of the Services.

6.2 Paysell imposes on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to you for a sub-processor's performance.

6.3 The current sub-processors are:

Sub-processorPurposeLocation
[[Hosting provider]]Server and database hosting[[Hosting location]]
[[Blockchain data provider]]TON node access and transaction data[[Provider location]]
[[E-mail delivery provider]]Transactional e-mail (verification, notifications)[[Provider location]]
[[Other sub-processor]][[Purpose]][[Location]]

6.4 Paysell will give at least 30 days' notice, by e-mail or in the cabinet, before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period; if the objection cannot be resolved, either party may terminate the affected Services without penalty other than fees already accrued.

7. International transfers#

7.1 Personal data may be processed in [[Hosting location]] and in the locations of the sub-processors listed above.

7.2 Where a transfer is made from the European Economic Area, the United Kingdom or another jurisdiction that restricts transfers, it will be made under an adequacy decision where one applies, or otherwise under [[Transfer mechanism — e.g. EU Standard Contractual Clauses (2021/914), Modules Two and Three, with the UK Addendum where relevant]], which are incorporated into this DPA by reference and completed with the details in clause 2 and Annex information available on request.

Owner note: the transfer mechanism must be confirmed with counsel before this DPA is offered to merchants established in the EEA or the UK.

8. Personal data breaches#

8.1 Paysell will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data processed on your behalf.

8.2 The notification will describe, so far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point.

8.3 Notification is not an admission of fault or liability by Paysell.

8.4 You remain responsible for notifying your supervisory authority and your data subjects where the law requires it.

9. Audits#

9.1 Paysell will respond to reasonable written questions about its processing and security measures, and will provide any third-party audit report or certification it holds.

9.2 Where that is insufficient to demonstrate compliance, you may audit Paysell no more than once in any twelve months, on at least 30 days' written notice, during business hours, without unreasonable disruption, subject to confidentiality, and at your cost. An audit must not extend to another merchant's data or to information that would compromise the security of the Services.

9.3 A supervisory authority with lawful power may audit at any time.

10. Deletion and return#

10.1 On termination of the Services, Paysell will delete or return personal data processed on your behalf within [[Deletion period — e.g. 90 days]] of your request.

10.2 Paysell may retain data where required by law, including financial records and anti-money-laundering records retained for [[Record retention period — e.g. 5 years]], and may retain data in backups until those backups expire in the ordinary course. Retained data remains subject to this DPA.

10.3 On-chain data cannot be deleted, as described in clause 5.3.

11. Liability and term#

11.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, to the extent permitted by applicable law.

11.2 This DPA takes effect when you accept the Terms of Service and continues while Paysell processes personal data on your behalf.

11.3 Paysell may update this DPA where necessary to reflect a change in law, in sub-processors or in the Services, in the manner described in the Terms of Service.

12. Governing law#

This DPA is governed by [[Governing law]] and is subject to the dispute resolution provisions of the Terms of Service, except where mandatory data protection law requires otherwise.

Contact#

[[Company legal name]], [[Registered address]], [[Jurisdiction]]

  • Data protection contact / DPO: [[DPO email]]
  • Privacy requests and this DPA: [[Legal email]]
  • General support: [[Support email]]
← Все документы
Содержание
  • 1. Parties, scope and roles
  • 2. Subject matter and details of processing
  • 3. Obligations of the Merchant as controller
  • 4. Obligations of Paysell as processor
  • 5. Security measures
  • 6. Sub-processors
  • 7. International transfers
  • 8. Personal data breaches
  • 9. Audits
  • 10. Deletion and return
  • 11. Liability and term
  • 12. Governing law
  • Contact
Содержание
  • 1. Parties, scope and roles
  • 2. Subject matter and details of processing
  • 3. Obligations of the Merchant as controller
  • 4. Obligations of Paysell as processor
  • 5. Security measures
  • 6. Sub-processors
  • 7. International transfers
  • 8. Personal data breaches
  • 9. Audits
  • 10. Deletion and return
  • 11. Liability and term
  • 12. Governing law
  • Contact

Остались вопросы?

Если что-то здесь непонятно или нужен подписанный экземпляр — напишите нам.

Написать в поддержку

Связанные документы

Terms of ServiceAPI and Developer TermsFee Schedule and Limits
Paysell

Криптоплатежи для онлайн-бизнеса: быстро, без чарджбэков и лишней бюрократии.

Продукт

  • Как это работает
  • Тарифы
  • Способы оплаты
  • Безопасность
  • Вопросы
  • Блог

Решения

  • Интернет-магазины
  • Цифровые товары
  • SaaS и подписки
  • Онлайн-образование
  • Фриланс и услуги
  • Игры
  • Гемблинг
  • Трейдинг и биржи
  • Все решения

Разработчикам

  • Документация
  • Быстрый старт
  • Вебхуки
  • Справочник API (OpenAPI)
  • llms.txt для ИИ-агентов
  • Войти
  • Создать аккаунт

Документы

  • Условия использования
  • Политика конфиденциальности
  • Тарифы и лимиты
  • Допустимое использование и запрещённые виды бизнеса
  • Политика AML/CTF и санкций
  • Политика верификации мерчантов (KYC/KYB)
  • Возвраты и споры
  • Раскрытие рисков крипто-активов
  • Все юридические документы

© 2026 Paysell

Paysell — платёжный сервис для крипто-активов. Средства на балансе не являются банковским вкладом, а стоимость крипто-активов зависит от рынка.