Skip to content

Data Processing Agreement

Last updated: 30 August 2026 · version 1.0

This DPA applies whenever Payshen processes personal data on your behalf. It is incorporated into the Terms of Service and takes effect when you create a workspace - you do not need to sign a separate copy, though we will sign one on request.

The contracting party is BCE Ventures LLC, 30 N Gould St, Sheridan, WY 82801, United States. Because we are established in the United States, we are the data importer for customers in the EEA, the UK and Switzerland: the Standard Contractual Clauses in Annex D are offered by us, already completed, rather than requested from you.

Status: prepared for external data-protection counsel and pending their sign-off. It states our actual practice, verified against the running product. Where a commitment depends on something not yet in place, it says so rather than promising it.

1.Roles, scope and duration

1.1Who is what

For Customer Personal Data you or your users put into a workspace, you are the controller (or a processor acting for your own customer) and Payshen is the processor. Where you are yourself a processor - a platform onboarding sub-merchants, for example - we are your sub-processor, and Module Three of the SCCs applies instead of Module Two.

For account data, sign-in and security records, billing and sales correspondence, Payshen is an independent controller. That processing is described in the Privacy Policy and is not governed by this DPA.

A payment provider you apply to or route through is a separate and independent controller for what it receives. We are not a joint controller with any provider, and we do not determine what a provider does with an application once you have shared it.

1.2Duration

This DPA runs for as long as we process Customer Personal Data for you, and its obligations that by their nature survive - confidentiality, deletion, and the transfer mechanisms - carry on after the Terms end until deletion is complete.

1.3Order of precedence

If an order form, this DPA, the SCCs and the Terms conflict, the SCCs prevail over this DPA, this DPA prevails over the Terms, and an executed order form prevails over all three for the customer that signed it.

2.Processing only on your instructions

2.1The instruction

We process Customer Personal Data only on your documented instructions. Your use of the Service - the API calls you make, the routing rules you configure, the documents you share with a provider - is itself that instruction, together with the Terms and any order form.

2.2What we will not do

  • We do not sell Customer Personal Data, share it for cross-context behavioural advertising, or use it for advertising of any kind.
  • We do not use it to train machine-learning models that serve anyone other than you. The routing engine learns from your workspace's own outcomes and its learned state is scoped to your workspace; it is never pooled across customers.
  • We do not combine it with personal data we receive from another customer, or from a third party, except as needed to provide the Service to you.
  • We retain, use and disclose it only for the purposes in this DPA. Under US state law these are the commitments that make us a service provider or processor rather than a third party or a seller.

2.3Unlawful instructions

If we consider an instruction to infringe applicable data protection law, we will tell you without undue delay and may suspend the affected processing until it is resolved.

2.4Compelled disclosure

If law compels us to process beyond your instructions, we will inform you before processing unless that law prohibits it on important grounds of public interest. Government access requests are handled under clause 7.4.

3.Subject matter, categories and data subjects

This is Annex I(B) of the SCCs and the Article 30 record you need from us. It describes what the product actually processes, which is narrower than most payment platforms because no cardholder data reaches us at all - see clause 4.3.

ItemDetail
Subject matterProvision of the Payshen payment orchestration and provider-connectivity platform
Nature and purposeRouting payment requests to providers, recording outcomes, reconciling settlement, managing provider applications and the document vault, and reporting
DurationThe term of the Terms of Service, plus the deletion window in clause 9
Categories of data subjectYour personnel who use the workspace; your customers whose payments are routed; and the directors, beneficial owners and signatories named in onboarding documents you upload
Categories of personal dataIdentifiers (email, name, workspace role), payment metadata (amount, currency, country, method, card brand and last-four where a provider returns it, reference, outcome, decline reason), technical data (IP address, session and audit records), business records (entities, brands, provider applications), and the contents of documents you choose to upload
Special category dataNot requested and not required by the Service. Onboarding documents you upload may incidentally contain it - a passport image showing nationality, for example. You decide what to upload; we apply the measures in Annex B to all vault contents equally
Criminal offence dataNot processed by design. Sanctions and adverse-media screening is performed by your provider, not by us
FrequencyContinuous, for as long as the workspace is active

4.Security of processing

4.1Measures

We implement the technical and organisational measures in Annex B, which is Annex II of the SCCs. Those measures are described specifically enough to be checked, because a list of adjectives is not a commitment.

4.2Confidentiality

Everyone we authorise to process Customer Personal Data is bound by confidentiality obligations that survive the end of their engagement, and access is granted on a need-to-know basis.

4.3Cardholder data is out of scope

The Service is architected so that primary account numbers and authentication data never reach us: payment details are collected on a page controlled by your provider, and our systems hold only the metadata listed in clause 3. We are therefore not a PCI DSS card-data environment. If a future release changes that, this DPA will change with it and you will be told before it takes effect.

5.Sub-processors

5.1General authorisation

You give a general authorisation for us to engage sub-processors. The current list is below and is maintained on this page.

Sub-processorPurposeProcessing locationTransfer mechanism
Vercel Inc.Application hosting, edge network, and encrypted document storageUnited States, with edge processing in the customer's regionEU SCCs and the UK Addendum in Vercel's data processing addendum
Neon Inc.Managed PostgreSQL database holding workspace recordsEuropean Union (Frankfurt) for production dataProcessing in the EU; EU SCCs for any support access from the US
Resend (Plus Five Five, Inc.)Transactional email - sign-in links, invitations, notificationsUnited StatesEU SCCs and the UK Addendum in Resend's data processing addendum

5.2Changes and objection

We will give you at least 30 days' notice before a new sub-processor starts processing, by email to workspace owners and by updating this page. You may object on reasonable data-protection grounds within that period. If we cannot accommodate the objection, you may terminate the affected Service without penalty and receive a pro-rata refund of prepaid fees.

5.3Our responsibility for them

Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than this DPA, and we remain fully liable to you for their performance.

6.Assistance we owe you

6.1Data subject requests

The product is built so that most requests need no help from us: workspace owners can search and export payment data, read the audit trail, manage documents, and delete the workspace and everything in it. Where a request still needs us, we will assist by appropriate technical and organisational measures, taking into account the nature of the processing.

If a data subject contacts us directly about data we hold for you, we will not respond substantively. We will tell them to contact you and forward the request without undue delay.

6.2DPIAs and prior consultation

We will provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority, to the extent it relates to our processing and the information is not already in this DPA or the Privacy Policy.

6.3Personal data breach

We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point - and where we cannot provide all of it at once, we will provide it in phases rather than delay the first notice.

We will not notify a supervisory authority or any data subject on your behalf unless you instruct us to, or law requires us to.

7.International transfers

7.1The direction of travel

We are established in Wyoming, USA. Personal data you send us is therefore transferred to the United States, and we are the importer. Production database storage is in the European Union; application hosting, email delivery and support access involve the United States.

7.2EEA transfers

The Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 are incorporated into this DPA and completed in Annex D. Module Two applies where you are a controller; Module Three where you are a processor. This covers customers in every EEA state, including Cyprus and Malta.

7.3UK and Swiss transfers

For the UK, the International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018 applies to the SCCs, completed in Annex D. For Switzerland, the SCCs apply with the variations in Annex D so that the Federal Data Protection and Information Commissioner is the competent authority and references to the GDPR are read as references to the nFADP.

7.4Government access

This is the part of a US importer's commitments that actually matters after Schrems II, so it is stated rather than assumed. If we receive a legally binding request from a public authority for Customer Personal Data, we will:

  • notify you before disclosing, unless legally prohibited;
  • where prohibited, use reasonable efforts to obtain a waiver of that prohibition and to be permitted to tell you as much as we can, as soon as we can;
  • challenge the request where there is a reasonable basis to consider it unlawful under the law of the requesting authority or applicable international obligations, and pursue available appeals;
  • disclose only the minimum amount of data reasonably necessary on a permissible interpretation of the request; and
  • keep and make available to you a record of such requests.

We have never received a request from a public authority for Customer Personal Data, and we are not subject to any order that would prevent us from saying so.

Assessment of our exposure: we are a private company that is not an electronic communications service provider within the meaning of 50 U.S.C. § 1881(b)(4), and to our knowledge we do not fall within the scope of FISA Section 702. Executive Order 12333 confers no power to compel disclosure. We hold no cardholder data, and workspace contents are encrypted at rest under keys we hold - which reduces, but does not eliminate, what a compelled disclosure could yield.

7.5Data Privacy Framework

We are not currently self-certified to the EU-U.S. Data Privacy Framework, its UK Extension, or the Swiss-U.S. framework, and this page will say so until we are. The SCCs in Annex D are the mechanism we rely on today.

8.Audit and information rights

8.1Information

We will make available all information reasonably necessary to demonstrate compliance with Article 28 obligations, including this DPA, the Privacy Policy, and our security documentation.

8.2Audits

You may audit our compliance once in any twelve-month period, and additionally after a personal data breach affecting your data or where a supervisory authority requires it. Give us 30 days' written notice; audits happen during business hours, must not unreasonably disrupt the Service, and are subject to confidentiality. Where an independent report covers the scope of your audit, providing it satisfies this clause.

We do not currently hold a SOC 2 or ISO 27001 report. Saying so is more useful to your assessment than an ambiguous answer, and it is on the roadmap rather than in place.

9.Return and deletion

9.1During the term

You can export payment data as CSV and delete your workspace yourself at any time. Deleting a workspace deletes its members, payments, providers, business records, documents and audit entries by database cascade.

9.2After the term

At your choice we will return or delete Customer Personal Data at the end of the Terms. Absent an instruction within 30 days of termination, we will delete it. Backups are overwritten on their ordinary cycle and are deleted no later than 35 days after the primary data; until then they remain subject to this DPA and are not restored except for disaster recovery.

9.3What we keep

We retain the minimum required by law - billing records and the security audit trail - and only for as long as the law requires.

10.Annex A - Regional terms

These apply in addition to the clauses above, for customers and data subjects in the regions named. Where a regional term conflicts with a general clause, the regional term wins for that region.

A.1European Economic Area, including Cyprus and Malta

This DPA is the Article 28(3) contract. We have no establishment in the EEA, so no one-stop-shop lead authority applies and any competent supervisory authority - including the Office of the Commissioner for Personal Data Protection in Cyprus and the Information and Data Protection Commissioner in Malta - may act.

We have not yet designated an Article 27 representative in the Union. One will be appointed before we market to EEA customers, and named here and in the Privacy Policy when it is. We state this rather than leaving it silent, because its absence is the kind of thing a supervisory authority notices first.

A.2United Kingdom

UK GDPR and the Data Protection Act 2018 apply. The ICO is the competent authority, and the IDTA in Annex D governs transfers. A UK Article 27 representative has not yet been designated and will be named here when it is.

A.3Switzerland

The nFADP applies, the FDPIC is the competent authority, and the term “personal data” includes data about legal entities for as long as Swiss law provides it.

A.4United States

For the CCPA as amended by the CPRA, we are a service provider; for Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland and Tennessee we are a processor. In every case:

  • We do not sell or share personal information as those terms are defined, and we receive no consideration for it. Clause 2.2 is the operative restriction.
  • We will not retain, use or disclose personal information outside the direct business relationship, or for a purpose other than the business purposes specified in this DPA.
  • We will comply with applicable obligations and provide the same level of protection required of you; we will notify you if we determine we can no longer meet them, and you may take reasonable steps to stop and remediate unauthorised use.
  • We will assist with consumer requests to know, delete, correct, opt out and limit, and will pass on requests we receive directly.
  • Deidentified data, if any, will not be re-identified, and we will maintain the required controls and commitments.

We do not process personal information of consumers we know to be under 16, and the Service is not directed to children.

A.5Canada, including Quebec

Under PIPEDA we process personal information on your behalf and provide a comparable level of protection through this DPA and Annex B. In Quebec, under the Act as amended by Law 25:

  • We confirm the processing of personal information outside Quebec, principally in the United States and the European Union, and will provide the information you need for your privacy impact assessment on request.
  • We will notify you of any confidentiality incident without delay under clause 6.3, so that you can assess the risk of serious injury and keep your incident register.
  • We do not use personal information to render a decision based exclusively on automated processing about an individual. The routing engine decides between payment providers, not about people, and it produces no legal or similarly significant effect on a data subject.

A.6Middle East

For customers in the United Arab Emirates, the Federal Personal Data Protection Law applies and we act on your instructions as processor. For customers established in the DIFC, Data Protection Law No. 5 of 2020 applies, including its Article 28 processor requirements and its transfer rules, and this DPA is intended to satisfy them. For the ADGM, the Data Protection Regulations 2021 apply on the same basis. For the Kingdom of Saudi Arabia, the Personal Data Protection Law and its implementing regulations apply, and we will support the transfer conditions they require. For Bahrain, the PDPL applies.

Where any of these regimes requires a specific transfer approval, contractual form or local filing that this DPA does not by itself satisfy, we will execute the additional documents reasonably required at no charge.

11.Annex B - Technical and organisational measures

This is Annex II of the SCCs. Each measure below is implemented in the product today and can be verified in the running system; measures we intend but have not implemented are listed separately at the end rather than folded in.

MeasureHow it is implemented
Encryption at restProvider credentials, webhook signing secrets and every uploaded document are encrypted with AES-256-GCM by the application before reaching any storage backend, under an envelope scheme with a rotatable key. Storage never holds plaintext.
Encryption in transitHTTPS enforced, HSTS set, and outbound webhooks refused over plain HTTP outside local development.
PseudonymisationSession tokens, API keys and magic-link tokens are stored only as hashes. Secrets are displayed once at creation and are not recoverable afterwards.
Access controlCapability-scoped roles enforced server-side on every state-changing action, not only in the interface. Workspace isolation is applied in the data layer; a request scoped to another workspace returns not-found rather than a permission error.
AuthenticationPasswordless sign-in by single-use emailed link, with optional TOTP second factor and hashed recovery codes. Sessions expire after 30 days and can be revoked centrally.
Document accessVault documents are served only through routes that authorise first; a share is per document and per application, and revoking one takes effect on the next request.
Logging and accountabilityAn append-only audit trail records actor, action, target, IP and time for security-relevant and money-moving actions, and is exportable by the customer.
Network egress controlOutbound webhook targets are vetted against private, loopback, link-local and cloud-metadata ranges with DNS resolution at delivery time, and the connection is pinned to the vetted address to defeat rebinding.
Input handlingRequest bodies are size-capped, inputs schema-validated, and database access is fully parameterised through a typed query builder.
Resilience and integrityMoney-moving operations use an atomic claim-first protocol so a retry or a concurrent request cannot double-capture or double-refund, and API writes accept an idempotency key that replays the original response.
Segregation of environmentsProduction, staging and demo run as separate deployments against separate databases. Test and live traffic are separated within a workspace and are never added together in reporting.
DeletionAutomated retention windows are enforced by a scheduled job; workspace deletion cascades across all related records.
Supplier managementSub-processors are contracted with terms no less protective than this DPA, and listed publicly in clause 5.

Not yet in place, stated so your assessment is accurate: an independent security certification (SOC 2 or ISO 27001), a rehearsed restore from backup, and centralised security monitoring with alerting. Each is on the roadmap. A DPA that listed them as implemented would be the one thing in this document that could not survive an audit.

12.Annex C - Contact

Data protection contact for both parties' purposes, including SCC Annex I(A):

FieldDetail
Data importer / processorBCE Ventures LLC
Address30 N Gould St, Sheridan, WY 82801, United States
RoleProcessor (Module Two) or sub-processor (Module Three)
ActivitiesProvision of the Payshen payment orchestration platform
Contactthe contact form, marked for the attention of the data protection contact
Data exporter / controllerThe customer identified in the order form or workspace registration, at the address given there

We have not appointed a statutory Data Protection Officer. On our current scale and processing, Article 37 does not require one; the position is reviewed as the product grows and DIFC and UAE thresholds are assessed separately.

13.Annex D - Standard Contractual Clauses, UK Addendum and Swiss variations

The clauses are incorporated by reference and completed here, so that a reviewer does not have to guess which options we chose. Executing the Terms executes these.

D.1EU Standard Contractual Clauses (2021/914)

ClauseSelection
ModuleModule Two (controller to processor) where you are a controller; Module Three (processor to processor) where you are a processor
Clause 7 - dockingIncluded
Clause 9 - sub-processorsOption 2, general written authorisation, with 30 days' notice as in clause 5.2
Clause 11 - redressThe optional independent dispute resolution body is not selected
Clause 17 - governing lawThe law of Ireland
Clause 18 - forumThe courts of Ireland
Annex I(A) - partiesAs set out in Annex C
Annex I(B) - descriptionAs set out in clause 3
Annex I(C) - competent authorityThe supervisory authority of the EEA state in which the data exporter is established; for an exporter relying on Article 3(2), the authority of the member state where its representative is established
Annex II - measuresAs set out in Annex B
Annex III - sub-processorsAs set out in clause 5

Irish law is chosen for clause 17 because it is an EEA law that allows third-party beneficiary rights, and choosing the exporter's own law would require a different completed set per customer. A customer that needs its own member state's law can have it on request in an order form.

D.2UK International Data Transfer Addendum (version B1.0)

TableEntry
Table 1 - partiesExporter: the customer. Importer: BCE Ventures LLC, 30 N Gould St, Sheridan, WY 82801, United States
Table 2 - selected SCCsThe EU SCCs completed in D.1, Module Two or Three as applicable
Table 3 - appendix informationAnnex I as per Annex C and clause 3; Annex II as per Annex B; Annex III as per clause 5
Table 4 - ending the AddendumNeither party may end the Addendum when the Approved Addendum changes

D.3Swiss variations

  • The competent supervisory authority is the Federal Data Protection and Information Commissioner.
  • References to the GDPR are read as references to the nFADP, and references to member state law as references to Swiss law.
  • “Personal data” includes data relating to legal entities until Swiss law provides otherwise.
  • Data subjects in Switzerland may enforce their third-party beneficiary rights in Switzerland.

D.4Conflict

Nothing in this DPA is intended to conflict with the SCCs or the UK Addendum. Where it does, they prevail.

14.Liability and changes

10.1Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, except that nothing limits either party's liability to a data subject under the third-party beneficiary rights in the SCCs, or any liability that cannot be limited by law.

10.2Changes

We may update this DPA where a change in law, a new sub-processor, or a change to the Service requires it. Material changes are notified to workspace owners at least 30 days before they take effect, the version and date at the top of this page always identify the current text, and superseded versions are available on request.

10.3Signature

Accepting the Terms or using the Service accepts this DPA. If your procurement process needs a signed copy, ask through the contact form and we will sign this text without negotiation, which is faster for both of us than redlining it.

Data Processing Agreement - Payshen