Tłumaczenie to jest dostarczane dla wygody. Wersja angielska jest wersją wiążącą prawnie.
1. Who is who
For personal data contained in your orders and invoices, you the merchant are the data controller, and the Operator of the Payora instance acts as processor on your documented instructions. For your own merchant account data, the Operator is the controller. For this instance, the Operator is Payora, the operator of payora.money, reachable at the address below; the registered legal entity and address are named in the signed copy, which is issued on request before any processing you rely on this DPA for. Contact: support@payora.money.
2. Subject-matter and duration
Subject-matter: processing personal data as needed to run crypto payment acceptance, balances, transfers and payouts for you. Duration: for as long as your account exists, plus any period the Operator must retain records to meet accounting and legal obligations. See Data Retention.
3. Nature and purpose
Creating and settling invoices, matching on-chain deposits to invoices, maintaining an append-only ledger balance, processing transfers and payout requests, sending webhooks to the URL you configure, and preventing fraud and abuse.
4. Categories of data subjects
Your customers who pay an invoice, and any individual whose details you choose to attach to an invoice.
5. Categories of personal data
Optional merchant-supplied customer email, name and notes on an invoice. Invoice and settlement records, including public blockchain addresses and transaction identifiers. Minimal request metadata: IP address, timestamp and user-agent, kept for security, rate-limiting and fraud prevention.
No special categories of data are required by the service. Do not put them in invoice notes. Payora never stores private keys, seed phrases or card numbers.
6. Processor obligations
6.1 Documented instructions
The Operator processes personal data only on your documented instructions, which include your use of the product and its API, unless required otherwise by law.
6.2 Confidentiality
People authorised to process the data are bound to confidentiality.
6.3 Security (Art. 32)
The Operator maintains technical and organisational measures appropriate to the risk. The concrete controls are listed on the Security page and include HMAC-signed API requests and webhooks, encryption of the API secret at rest with AES-256-GCM, bcrypt password hashing, optional TOTP two-factor authentication, revocable sessions, CSRF tokens, rate limiting, transport security headers, SSRF-guarded outbound webhooks, an append-only settlements ledger and offline key custody.
6.4 Subprocessors
You give general authorisation for the subprocessors listed on the Subprocessors page. The Operator will give notice of intended changes so you can object. Before engaging a subprocessor that processes personal data on your behalf, the Operator will put in place terms no less protective than this DPA.
6.5 Assistance
The Operator will help you, taking into account the nature of the processing, to respond to data-subject requests, and to meet your obligations on security, breach notification and impact assessments.
6.6 Breach notification
The Operator will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information available at the time.
6.7 Deletion or return
On termination, the Operator will delete or return the personal data processed for you, except where retention is legally required. See Data Retention.
6.8 Audit
The Operator will make available the information needed to show compliance with this DPA, and will allow and contribute to audits, on reasonable notice and subject to confidentiality.
7. International transfers
Some subprocessors operate outside your country. Where personal data is transferred out of the EEA or UK without an adequacy decision, the Operator will rely on Standard Contractual Clauses or another lawful transfer mechanism, and is responsible for having that mechanism in place for their instance. Note that most of the third parties Payora contacts, such as blockchain data providers and price feeds, receive no personal data at all: only a public address or a price query.
8. How to accept this DPA
The counterparty is the Operator of this instance, not the software. If you need a signed copy naming the legal entity, or a different form of agreement, contact support@payora.money.
Last updated: 16 July 2026. If we make material changes to this page, the updated version will be posted here.