This Data Processing Addendum ("DPA") forms part of the Terms of Service between Paidback Technologies, LLC ("Processor," "we") and the merchant installing the Paidback application ("Controller," "you"). By installing Paidback, you accept this DPA. No signature is required.
Where this DPA conflicts with the Terms of Service in relation to the processing of personal data, this DPA prevails.
Terms including "personal data," "processing," "controller," "processor," "data subject," "personal data breach," and "supervisory authority" have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and, where applicable, the UK GDPR and Data Protection Act 2018.
"Data Protection Laws" means all laws applicable to the processing of personal data under this DPA, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, and applicable US state privacy laws.
"Subprocessor" means any third party engaged by us to process personal data on your behalf.
You are the Controller of your customers' personal data. We are the Processor. We process that personal data only on your documented instructions.
Your instructions consist of this DPA, the Terms of Service, and your configuration of the Paidback application. Installing the app and connecting a payment provider constitutes an instruction to process disputes for that provider.
We are an independent controller with respect to your own merchant account data (your name, email, store details, and billing records). That processing is governed by our Privacy Policy, not by this DPA.
Subject matter: Provision of automated chargeback and payment dispute defense.
Duration: For as long as the Paidback application is installed, plus the retention periods set out in our Privacy Policy.
Nature and purpose: Collection, structuring, storage, analysis, and transmission of order and customer data for the purpose of assembling and submitting dispute evidence to payment providers.
Categories of data subjects: Your customers who are party to a disputed transaction.
Categories of personal data:
Special categories of data: None. Paidback is not designed to process special category data under Article 9, and you must not configure it to do so.
We will:
(a) Process personal data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law — in which case we will inform you before processing, unless the law prohibits that notice.
(b) Ensure that all personnel authorized to process personal data are bound by confidentiality obligations.
(c) Implement and maintain the technical and organizational measures described in Annex A.
(d) Respect the conditions in Section 5 for engaging Subprocessors.
(e) Assist you, by appropriate technical and organizational measures and insofar as possible, in fulfilling your obligation to respond to data subject requests.
(f) Assist you in ensuring compliance with your obligations under Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to us.
(g) At your choice, delete or return all personal data at the end of the provision of services, and delete existing copies, unless retention is required by law.
(h) Make available to you all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as described in Section 8.
(i) Immediately inform you if, in our opinion, an instruction infringes Data Protection Laws.
You grant us general authorization to engage Subprocessors. Our current Subprocessors are listed at paidback.io/subprocessors.
We will give you at least 30 days' notice before adding or replacing a Subprocessor that processes customer personal data. Notice will be sent to the email address associated with your Shopify account. If you object on reasonable data protection grounds within that period, we will work with you in good faith to find an alternative. If no alternative is available, you may terminate this DPA and the Terms of Service by uninstalling the application, without penalty and without liability for future fees.
We impose on each Subprocessor, by written contract, data protection obligations no less protective than those in this DPA. We remain fully liable to you for the performance of each Subprocessor's obligations.
Personal data processed under this DPA is transferred to and processed in the United States.
For transfers of personal data from the EEA, the parties incorporate the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), which are hereby incorporated by reference and completed as follows:
For transfers from the United Kingdom, the parties incorporate the UK International Data Transfer Addendum to the EU SCCs (Version B1.0), with Tables 1 to 4 populated by the corresponding provisions of this DPA, and with the Importer able to end the Addendum as set out in Section 19.
For transfers from Switzerland, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, references to supervisory authorities include the Swiss Federal Data Protection and Information Commissioner, and the SCCs also protect the data of legal entities until Swiss law provides otherwise.
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data processed under this DPA.
Our notification will include, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where full information is not immediately available, we will provide it in phases without undue further delay.
You are responsible for any notification to supervisory authorities or data subjects. We will provide reasonable cooperation and information to enable you to do so.
We will make available to you, on request and no more than once per calendar year, information reasonably necessary to demonstrate compliance with this DPA. This may include our security documentation, subprocessor list, and responses to a reasonable security questionnaire.
Where you can demonstrate that this information is insufficient to meet a specific regulatory obligation, we will cooperate with an audit conducted by you or an independent auditor. Audits must be requested at least 30 days in advance, conducted during normal business hours, subject to confidentiality obligations, and must not unreasonably disrupt our operations. You bear the cost of any audit unless it reveals a material breach of this DPA.
If we receive a request from one of your customers to exercise their rights, we will not respond directly except to acknowledge receipt and refer them to you. We will notify you of the request without undue delay.
Shopify's customers/data_request and customers/redact webhooks are the primary mechanism by which such requests reach us. We honor them within 30 days.
On uninstallation of the application, or on your written request, we will delete all customer personal data within 30 days, other than data we are required by law to retain. Anonymized dispute outcome records that cannot identify a data subject are not personal data and may be retained.
On request made before deletion, we will provide you with a copy of the personal data we hold in a structured, commonly used, machine-readable format.
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where Data Protection Laws prohibit such limitation.
This DPA takes effect on installation of the Paidback application and continues until all personal data has been deleted or returned in accordance with Section 10.
Encryption
Access control
Data minimization
Resilience and recovery
Logging and monitoring
Software security
Organizational
The current list of Subprocessors, including the data each receives and its processing region, is maintained at paidback.io/subprocessors and forms part of this DPA.
Paidback Technologies, LLC
Delaware, United States
support@paidback.io