सामग्री पर जाएं
कानूनी

Data Processing Agreement

The terms on which the Operator processes personal data that you, the merchant, put into your orders.

Last updated 16 जुलाई 20263 मिनट पढ़ेंSections: 8

1. Who is who

For personal data contained in your orders and invoices, you the merchant are the data controller, and the Operator of the Payora instance acts as processor on your documented instructions. For your own merchant account data, the Operator is the controller. For this instance, the Operator is Payora, the operator of payora.money, reachable at the address below; the registered legal entity and address are named in the signed copy, which is issued on request before any processing you rely on this DPA for. Contact: support@payora.money.

2. Subject-matter and duration

Subject-matter: processing personal data as needed to run crypto payment acceptance, balances, transfers and payouts for you. Duration: for as long as your account exists, plus any period the Operator must retain records to meet accounting and legal obligations. See Data Retention.

3. Nature and purpose

Creating and settling invoices, matching on-chain deposits to invoices, maintaining an append-only ledger balance, processing transfers and payout requests, sending webhooks to the URL you configure, and preventing fraud and abuse.

4. Categories of data subjects

Your customers who pay an invoice, and any individual whose details you choose to attach to an invoice.

5. Categories of personal data

Optional merchant-supplied customer email, name and notes on an invoice. Invoice and settlement records, including public blockchain addresses and transaction identifiers. Minimal request metadata: IP address, timestamp and user-agent, kept for security, rate-limiting and fraud prevention.

No special categories of data are required by the service. Do not put them in invoice notes. Payora never stores private keys, seed phrases or card numbers.

6. Processor obligations

6.1 Documented instructions

The Operator processes personal data only on your documented instructions, which include your use of the product and its API, unless required otherwise by law.

6.2 Confidentiality

People authorised to process the data are bound to confidentiality.

6.3 Security (Art. 32)

The Operator maintains technical and organisational measures appropriate to the risk. The concrete controls are listed on the Security page and include HMAC-signed API requests and webhooks, encryption of the API secret at rest with AES-256-GCM, bcrypt password hashing, optional TOTP two-factor authentication, revocable sessions, CSRF tokens, rate limiting, transport security headers, SSRF-guarded outbound webhooks, an append-only settlements ledger and offline key custody.

6.4 Subprocessors

You give general authorisation for the subprocessors listed on the Subprocessors page. The Operator will give notice of intended changes so you can object. Before engaging a subprocessor that processes personal data on your behalf, the Operator will put in place terms no less protective than this DPA.

6.5 Assistance

The Operator will help you, taking into account the nature of the processing, to respond to data-subject requests, and to meet your obligations on security, breach notification and impact assessments.

6.6 Breach notification

The Operator will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information available at the time.

6.7 Deletion or return

On termination, the Operator will delete or return the personal data processed for you, except where retention is legally required. See Data Retention.

6.8 Audit

The Operator will make available the information needed to show compliance with this DPA, and will allow and contribute to audits, on reasonable notice and subject to confidentiality.

7. International transfers

Some subprocessors operate outside your country. Where personal data is transferred out of the EEA or UK without an adequacy decision, the Operator will rely on Standard Contractual Clauses or another lawful transfer mechanism, and is responsible for having that mechanism in place for their instance. Note that most of the third parties Payora contacts, such as blockchain data providers and price feeds, receive no personal data at all: only a public address or a price query.

8. How to accept this DPA

The counterparty is the Operator of this instance, not the software. If you need a signed copy naming the legal entity, or a different form of agreement, contact support@payora.money.

Last updated: 16 July 2026. If we make material changes to this page, the updated version will be posted here.

कानूनी

हर नीति, एक ही स्थान पर.

इस Payora उदाहरण को नियंत्रित करने वाले दस्तावेज़। अनुवाद सुविधा के लिए प्रदान किए गए हैं; अंग्रेजी संस्करण कानूनी रूप से बाध्यकारी है।

सेवा की शर्तेंखाते, धन की सुरक्षा, शुल्क और देयता।गोपनीयता नीतिकौन सा डेटा संग्रहीत है, कुकीज़ और आपके अधिकार।स्वीकृत उपयोग नीतिसेवा का उपयोग किस लिए नहीं किया जा सकता है, और इसे कैसे लागू किया जाता है।कुकी नीतिकौन से कुकीज़ सेट हैं, और क्यों।
डेटा प्रोसेसिंग समझौताव्यापारी और ऑपरेटर के बीच डेटा प्रोसेसिंग शर्तें।आप यहाँ हैं
उपप्रक्रियाएँहर तीसरा पक्ष जिससे सेवा संपर्क करती है।डेटा संरक्षण नीतिहर प्रकार के रिकॉर्ड को कितनी देर तक रखा जाता है।सुरक्षासुरक्षा नियंत्रण और कुंजियाँ कैसे रखी जाती हैं।जोखिम प्रकटीकरणक्रिप्टो को स्वीकार करने और रखने के असली जोखिम।रिफंड और चार्जबैककोई चार्जबैक नहीं, और रिफंड वास्तव में क्या है।
अक्सर पूछे जाने वाले प्रश्न

अक्सर पूछे जाने वाले प्रश्न

साफ जवाब, जिसमें असहज सवाल शामिल हैं: हिरासत, शुल्क और जब कुछ गलत होता है तो क्या होता है।

सहायता केंद्र

Who is the controller and who is the processor?

For personal data in your orders and invoices, you the merchant are the controller and the Operator of the Payora instance acts as processor on your documented instructions. For your own merchant account data, the Operator is the controller.

What personal data does the Operator process for me?

Optional customer email, name and notes that you attach to an invoice, invoice and settlement records including public addresses and transaction ids, and minimal request metadata such as IP, timestamp and user-agent for security and fraud prevention.

How are subprocessors authorised?

By general authorisation of the list on the Subprocessors page. The Operator gives notice of intended changes so you can object, and undertakes to put terms no less protective than this DPA in place with any subprocessor that processes personal data on your behalf.

What happens to the data when I leave?

On termination the Operator deletes or returns the personal data processed for you, except where retention is legally required for accounting or compliance. The Data Retention page sets out the default periods.

इस पृष्ठ का उत्तर क्या है