Legal
Data Processing Addendum
Version 2.4 — Last updated 1 July 2026. This DPA is incorporated by reference into the Paytab Terms of Service.
1. Preamble & structure
This Data Processing Addendum ("DPA") is entered into between the merchant identified in the Paytab account ("Customer") and Paytab Ltd, a company registered in England and Wales under number 15234567 ("Paytab"). It governs any Processing of Personal Data by Paytab on behalf of the Customer in the course of providing the Service under the Terms of Service (the "Agreement").
This DPA reflects the requirements of the UK GDPR, the Data Protection Act 2018, and — where the Customer is established in the EEA or Processing concerns EEA data subjects — the EU GDPR. Nothing in this DPA relieves Paytab of its independent obligations as a controller in respect of Paytab's own regulated activities (KYC, KYB, transaction monitoring, sanctions screening, safeguarding, fraud prevention and financial-crime reporting).
2. Definitions
Capitalised terms used but not defined here have the meanings given in the Agreement or in the UK GDPR. In particular, "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach", "Sub-processor" and "Supervisory Authority" bear their UK GDPR meanings. "End Customer Data" means Personal Data relating to the Customer's end customers that the Customer submits to, or that is generated by, the Service.
3. Roles of the parties
The parties acknowledge that in relation to End Customer Data submitted by the Customer through the Service (for example, the shipping name and address the Customer collects at checkout, or metadata the Customer attaches to a payment), the Customer acts as Controller and Paytab acts as Processor.
In relation to Personal Data that Paytab is legally required to collect and process in its own right — including cardholder authentication data, KYC/KYB records of the Customer's directors and beneficial owners, fraud signals, sanctions-screening results, chargeback and dispute records, and transaction data required for regulatory reporting — Paytab acts as an independent Controller. The Paytab Privacy Policy governs that Processing.
Where Paytab and the Customer both determine the purposes of certain Processing (for example, joint anti-fraud analytics), they act as joint controllers and this DPA sets out the essence of their arrangement under Article 26 UK GDPR.
4. Scope & duration of processing
The subject-matter, nature and purpose of Processing, the categories of Data Subjects and Personal Data, and the duration of Processing are set out in Annex I ("Processing Details") below. Processing takes place for the duration of the Agreement and, thereafter, only for the period strictly necessary to meet Paytab's legal, regulatory or defence-of-claims obligations.
Annex I — Processing Details
- Data Subjects: the Customer's end customers, prospects, employees and any third parties whose Personal Data the Customer submits through the Service.
- Categories of Personal Data: name; email; billing and shipping address; phone number; order and cart contents; last four digits of card; tokenised card reference; IP address; device and browser signals; free-text metadata the Customer chooses to attach.
- Special-category data: none is required. The Customer must not submit special-category data through free-text metadata.
- Purposes: to authorise, capture, settle, refund, dispute and report on payments; to issue receipts and invoices; to provide dashboards and analytics; to detect and prevent fraud.
- Duration: for the term of the Agreement plus statutory retention periods (typically 6 years for financial records under the MLRs 2017 and Companies Act 2006).
5. Processor obligations
When acting as Processor, Paytab will:
- Process End Customer Data only on documented instructions from the Customer, including the instructions embedded in the Customer's use of the Service and its documented configuration.
- Ensure that personnel authorised to Process End Customer Data are bound by written confidentiality obligations or a statutory duty of confidentiality.
- Implement and maintain the technical and organisational measures set out in Annex II (Security Measures).
- Assist the Customer, taking into account the nature of the Processing and information available to Paytab, in complying with Articles 32–36 UK GDPR (security, breach notification, DPIAs and prior consultation).
- Notify the Customer without undue delay if, in Paytab's opinion, an instruction infringes the UK GDPR or other data-protection law.
6. Sub-processors
The Customer provides general written authorisation for Paytab to engage sub-processors to Process End Customer Data. Paytab maintains a current list of sub-processors at paytab.co.uk/legal/sub-processors and will provide at least 30 days' notice of the addition or replacement of a sub-processor that Processes End Customer Data. The Customer may object on reasonable data-protection grounds during that period; if the parties cannot agree on a solution, the Customer may terminate the affected part of the Service without penalty.
Paytab remains fully liable to the Customer for any failure by a sub-processor to fulfil its data-protection obligations, and imposes on each sub-processor obligations no less protective than those in this DPA.
7. International data transfers
Where the transfer of End Customer Data outside the United Kingdom or the EEA would otherwise be restricted by the UK GDPR or the EU GDPR, the parties rely on the mechanisms below, in this order of preference:
- An applicable adequacy decision or adequacy regulation.
- The UK International Data Transfer Addendum ("UK IDTA") to the EU Standard Contractual Clauses, incorporated by reference and completed as set out in Annex III of this DPA.
- The 2021 EU Standard Contractual Clauses (Modules 2 and 3 as applicable) where the transfer originates in the EEA.
Paytab has completed and, where appropriate, will supply on request a Transfer Risk Assessment for each relevant transfer, and will implement supplementary technical, contractual and organisational measures where required by the ICO's guidance or by an applicable Supervisory Authority.
8. Security measures (Annex II)
Paytab implements and maintains the following technical and organisational measures, which are reviewed at least annually and updated to reflect changes in the threat landscape and applicable industry standards:
- ISO/IEC 27001:2022 aligned Information Security Management System, PCI DSS Level 1 Service Provider validation, SOC 2 Type II attestation (annually refreshed).
- Encryption of End Customer Data in transit (TLS 1.2+) and at rest (AES-256 with envelope encryption and hardware-backed key custody).
- Network segmentation, private-VPC production environments, mutual-TLS between internal services, and hardened container runtime with vulnerability scanning gated on deployment.
- Role-based access control, mandatory SSO with phishing-resistant MFA for personnel, just-in-time production access with approval workflow, and complete audit logging.
- Continuous logging and monitoring, 24/7 on-call response, quarterly internal and annual external penetration testing, and coordinated vulnerability disclosure via security@paytab.co.uk.
- Personnel security screening, security-awareness training on hire and at least annually thereafter, and role-appropriate secure-development training for engineers.
- Business continuity and disaster-recovery testing, off-region encrypted backups, and documented RPO/RTO targets (see Annex II §5 of the SLA).
9. Assistance & audits
Paytab will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA, including the latest SOC 2 Type II report, ISO 27001 certificate, PCI Attestation of Compliance and a completed CAIQ. Enterprise-plan Customers may, subject to reasonable notice, confidentiality and cost-recovery, conduct or mandate a third-party auditor to conduct an audit no more than once per twelve-month period, or more frequently where required by a Supervisory Authority. Paytab will assist the Customer with data-subject requests it cannot fulfil directly, and with DPIAs and prior consultations, in each case within a reasonable timeframe.
10. Personal data breach
Paytab will notify the Customer of a confirmed Personal Data Breach affecting End Customer Data without undue delay, and in any event within 72 hours of Paytab's Security team confirming the breach. The notification will describe the nature of the breach, the categories and approximate numbers of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its adverse effects. Paytab will provide reasonable assistance to the Customer in meeting its own notification obligations to Supervisory Authorities and Data Subjects.
11. Return or deletion of data
On termination or expiry of the Agreement, and at the Customer's written choice, Paytab will return or delete all End Customer Data in its possession or control, save to the extent that Paytab is required by Applicable Law (in particular the MLRs 2017 and scheme rules) to retain some or all of that data. Data retained for legal-obligation reasons will remain protected in accordance with this DPA.
12. Liability & precedence
Each party's liability under this DPA is subject to the exclusions and limitations of liability set out in the Agreement. In the event of any conflict between this DPA and the Agreement in relation to the Processing of Personal Data, this DPA prevails. In the event of any conflict between this DPA and the UK IDTA or the EU SCCs incorporated by reference, those cross-border transfer instruments prevail to the extent of the conflict.
13. Governing law
This DPA is governed by the laws of England and Wales and the courts of England and Wales have exclusive jurisdiction, save that either party may seek injunctive or equivalent relief in any court of competent jurisdiction to protect its intellectual property or Personal Data.
Merchants on the Growth and Enterprise plans can request a counter-signed copy of this DPA by emailing legal@paytab.co.uk.