Legal

Data Processing Agreement

Last updated: August 15, 2026

1. Definitions

Data Processor: PayRetrieve (the Service)
Data Controller: You (the Customer)
Personal Data: Any information relating to an identified or identifiable natural person processed by PayRetrieve on your behalf.
Subprocessor: Third-party service providers used by PayRetrieve to provide the Service.

2. Processing Details

  • Subject Matter: Processing of payment failure data and customer contact information for recovery purposes
  • Duration: For the duration of the Service agreement
  • Nature & Purpose: Automated payment recovery notification and tracking
  • Types of Personal Data: Customer email addresses, phone numbers, payment failure details, invoice amounts
  • Categories of Data Subjects: Your customers whose payments have failed

3. Processor Obligations

PayRetrieve agrees to:

  • Process Personal Data only on documented instructions from you
  • Ensure confidentiality of Personal Data
  • Implement appropriate technical and organizational security measures
  • Assist you in responding to data subject requests
  • Notify you of any Personal Data breaches without undue delay
  • Delete or return Personal Data upon termination of the Service
  • Make available information necessary to demonstrate compliance

4. Subprocessors

PayRetrieve uses the following Subprocessors:

  • Vercel: Application hosting
  • Neon: Database hosting
  • Stripe: Payment processing
  • Resend: Email delivery
  • Twilio: SMS delivery

We will notify you of any intended changes concerning the addition or replacement of Subprocessors, giving you the opportunity to object to such changes.

5. Security Measures

  • Encryption of data in transit (TLS 1.3)
  • Encryption of data at rest (AES-256)
  • Regular security assessments
  • Access controls and authentication
  • Network security protections
  • Incident response procedures

6. Data Subject Rights

PayRetrieve will assist you in responding to requests from data subjects exercising their rights under applicable data protection laws, including:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object

7. Data Transfers

Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA). Such transfers are made in compliance with applicable data protection laws using appropriate safeguards such as Standard Contractual Clauses.

8. Termination & Data Return

Upon termination of the Service, PayRetrieve will, at your choice, delete or return all Personal Data processed on your behalf, and delete existing copies unless required by law to retain the data.

9. Governing Law

This DPA is governed by the laws of the jurisdiction specified in the main Service Agreement.

10. Contact

For questions about this DPA or data protection matters, contact:
PayRetrieve
Email: privacy@payretrieve.online
Address: [Legal entity address to be added]