1. Parties & Incorporation
This DPA is entered into between the Customer identified on the account (“Customer”, acting as Controller) and Payment Recovery System (“Processor”, “we”, “us”).
It is incorporated into and forms part of the Terms of Service. Where this DPA conflicts with the Terms of Service or the Privacy Policy on a matter of personal data processing, this DPA prevails.
No signature is required: by creating an account and submitting Customer Personal Data to the Service, the Customer accepts this DPA on behalf of the entity it represents and warrants that it has authority to do so. Customers requiring an executed counterpart on their own paper should contact legal@paymentrecoverysystem.com.
2. Definitions
- “Data Protection Laws”means all laws applicable to the processing under this DPA, including Regulation (EU) 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss FADP, the California Consumer Privacy Act as amended (“CCPA”), and the Florida Digital Bill of Rights, Fla. Stat. §§ 501.701–501.722.
- “Customer Personal Data”means personal data contained in Customer Data that we process on the Customer’s behalf — principally data about the Customer’s own end-users whose charges have failed.
- “Controller”, “Processor”, “Data Subject”, “Personal Data Breach”, and “processing” have the meanings given in the GDPR.
- “SCCs” means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.
- “Sub-processor” means a third party engaged by us to process Customer Personal Data.
3. Roles of the Parties
For Customer Personal Data, the Customer is the Controller and Payment Recovery System is the Processor. The Customer determines the purposes and means of processing; we act only on the Customer’s instructions.
The Customer warrants that it has a lawful basis for the processing it instructs, that it has provided all notices and obtained all consents its own data subjects are entitled to, and that its instructions do not cause us to breach Data Protection Laws.
Where we act as Controller. We are an independent Controller — not a Processor — for (a) account-holder identity and billing data, (b) security, audit, and abuse-prevention logs, and (c) aggregated statistics that contain no personal data. That processing is governed by our Privacy Policy, not by this DPA.
Stripe.With respect to payment transactions, Stripe acts as an independent controller under its own terms. Neither party is the other’s processor for that processing.
4. Processing Instructions
We process Customer Personal Data only on the Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by law to which we are subject. Where such a legal requirement applies, we will inform the Customer before processing unless that law prohibits the notification on important grounds of public interest.
The Customer’s documented instructions consist of: this DPA, the Terms of Service, the configuration the Customer sets in the Service (campaigns, templates, retry schedules, integrations), and any further written instruction the parties agree.
We will inform the Customer if, in our opinion, an instruction infringes Data Protection Laws. We may suspend performance of the instruction until it is withdrawn, amended, or confirmed.
We do not:sell Customer Personal Data; share it for cross-context behavioural advertising; use it to train our own or any third party’s machine-learning models; or use it for any purpose other than providing and securing the Service.
5. Personnel & Confidentiality
We ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality — contractual or statutory — that survives the end of their engagement.
Access is limited to personnel who need it to perform their role, is granted on a least-privilege basis, is logged, and is revoked promptly on role change or departure.
6. Security Measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risk to data subjects, we implement appropriate technical and organisational measures under Article 32 GDPR. The measures in force are described in Annex II and on our Security page.
We may update those measures over time provided the update does not materially reduce the overall level of security.
7. Sub-processors
The Customer grants a general authorisation for us to engage Sub-processors, subject to this section. The Sub-processors authorised as at the effective date are listed in Annex III and maintained at Payment Recovery System Sub-processors.
We will give at least 30 days’ notice by email before a new Sub-processor begins processing. The Customer may object on reasonable data-protection grounds within the notice period; the objection procedure and its consequences — including a pro-rata refund where no alternative exists — are set out on the Sub-processors page.
Each Sub-processor is engaged under a written contract imposing data-protection obligations no less protective than those in this DPA. We remain fully liableto the Customer for each Sub-processor’s performance of its obligations, as required by Article 28(4).
8. Data Subject Rights
Taking into account the nature of the processing, we assist the Customer by appropriate technical and organisational measures — insofar as this is possible — in fulfilling its obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR.
The Service provides self-service means to satisfy most requests: the Customer can search, export, correct, and delete end-user records from the dashboard, and cascading account deletion removes all associated end-user data.
If a data subject contacts us directly about data we process for a Customer, we will not respond substantively. We will promptly forward the request to the Customer and confirm to the data subject that we have done so, unless legally prohibited from doing either.
Where a request cannot be satisfied through the Service’s own tooling, we will provide reasonable assistance at no charge for a reasonable volume of requests. Repetitive or manifestly excessive requests may be charged at our then-current professional-services rate on prior written notice.
9. Assistance with Articles 32–36
Taking into account the nature of processing and the information available to us, we assist the Customer in ensuring compliance with its obligations under:
- Article 32 — security of processing;
- Articles 33 and 34 — breach notification to supervisory authorities and data subjects;
- Article 35 — data protection impact assessments;
- Article 36 — prior consultation with supervisory authorities.
Annex I and Annex II are drafted to supply the information a Customer typically needs to complete a DPIA for a dunning workflow without having to ask us for it.
10. Personal Data Breach
We will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The 72-hour clock in Article 33(1) runs from the Controller’s awareness, so our 48-hour commitment is set to leave the Customer a working margin.
The notification will describe, to the extent known at the time:
- The nature of the breach, including the categories and approximate number of data subjects and records concerned;
- The likely consequences;
- The measures taken or proposed to address it and mitigate its effects;
- A contact point for further information.
Where the full picture is not available at first notification, we will provide information in phases as it is established, without further undue delay.
Because we operate from the State of Florida, United States, we also support the Customer’s obligations under the Florida Information Protection Act, Fla. Stat. § 501.171, which requires notice to affected Florida residents within 30 days of determination of a breach, and notice to the Florida Department of Legal Affairs where 500 or more Florida residents are affected.
Notification is not, and will not be construed as, an acknowledgement of fault or liability.
11. International Transfers
Customer Personal Data is processed in the United States. Where the Customer transfers personal data originating in the EEA, the United Kingdom, or Switzerland to us, the transfer is made under the SCCs, which are hereby incorporated into this DPA by reference and completed as follows:
- Module Two (Controller to Processor) applies to transfers from the Customer to us;
- Module Three (Processor to Processor) applies to onward transfers to our Sub-processors;
- Clause 7 (docking clause) applies;
- Clause 9(a): Option 2 — general written authorisation, with the 30-day notice period in Section 7;
- Clause 11(a): the optional independent dispute-resolution body is not selected;
- Clause 17: the SCCs are governed by the law of Ireland;
- Clause 18(b): disputes are resolved before the courts of Ireland;
- Annexes I, II, and III of the SCCs are populated by Annex I, Annex II, and Annex III of this DPA respectively.
For UK transfers, the SCCs apply as amended by the UK International Data Transfer Addendum (version B1.0), with Tables 1–4 completed by reference to this DPA and the importer’s ending of the Addendum permitted. For Swiss transfers, references to the GDPR are read as references to the FADP and references to supervisory authorities include the Swiss FDPIC.
We conduct a transfer impact assessment before engaging a new Sub-processor outside the EEA, and we will notify the Customer if we become unable to comply with the SCCs.
12. Return & Deletion
On termination or expiry of the Service, at the Customer’s choice, we will delete or return all Customer Personal Data and delete existing copies, unless retention is required by law.
In practice: the Customer has a 30-day window after termination to export its data through the Service. After that window, account data is permanently deleted. Encrypted backups are purged on their normal rolling schedule, which does not exceed 35 days; data remaining in backups is not accessed or restored during that period except to recover from a system failure.
We will certify deletion in writing on request. Where law requires retention — for example, transaction records retained for tax purposes — we will retain only the minimum data required, for the minimum period, and continue to protect it under this DPA.
13. Audits & Information
We make available to the Customer all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
The audit right is exercised as follows:
- In the first instance, by our providing our then-current security documentation, the information in Annex II, and written responses to a reasonable security questionnaire;
- Where that is genuinely insufficient to demonstrate compliance, by an on-site or remote audit on at least 30 days’ written notice, no more than once in any 12-month period (except following a Personal Data Breach or where required by a supervisory authority), during business hours, subject to confidentiality undertakings, and conducted so as not to disrupt the Service or the data of other customers;
- At the Customer’s cost, save where the audit reveals a material non-compliance, in which case we bear our own reasonable costs of remediation.
An auditor who is our competitor may be refused; the Customer may nominate an independent alternative.
14. U.S. State Privacy Law
California. With respect to personal information subject to the CCPA, we act as a Service Provider. We are prohibited from, and will not: (a) sell or share personal information; (b) retain, use, or disclose it for any purpose other than performing the services specified in the Terms, including for any commercial purpose of our own; (c) retain, use, or disclose it outside the direct business relationship with the Customer; or (d) combine it with personal information received from another source, except as permitted by CCPA regulations. We certify that we understand and will comply with these restrictions.
Florida. The Florida Digital Bill of Rights, Fla. Stat. §§ 501.701–501.722, imposes controller obligations on entities meeting its revenue and activity thresholds. Where the Customer is such a controller, we act as its processor and will comply with the processor duties in that statute, including assisting with consumer requests and maintaining a contract meeting its requirements. This DPA is that contract.
Other states. Where the Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, or a comparable state statute applies, we act as processor and comply with the equivalent processor obligations. This DPA is intended to satisfy the written-contract requirement of each such statute.
15. Liability & Term
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. Nothing in this DPA limits liability that cannot be limited under Data Protection Laws, including a data subject’s rights under Article 82 GDPR or Clause 12 of the SCCs.
This DPA takes effect when the Customer first submits Customer Personal Data to the Service and continues until all such data has been deleted or returned in accordance with Section 12. Sections 5, 12, 13, and 15 survive termination.
Annex I — Processing Details
Populates Annex I of the SCCs.
A. List of Parties
- Data exporter / Controller: the Customer identified on the account, at the contact details held on the account. Activities: operating a subscription business and instructing the recovery of failed payments. Signature and date: as per Section 1 (acceptance on account creation).
- Data importer / Processor: Payment Recovery System, contactable at legal@paymentrecoverysystem.com. Activities: providing the payment-recovery Service described in the Terms.
B. Description of Transfer
| Categories of data subjects | The Customer's end-users and customers whose payment has failed, is at risk of failing, or whose card is nearing expiry; and the Customer's own personnel who use the Service. |
|---|---|
| Categories of personal data | Name; email address; Stripe customer, invoice, and subscription identifiers; subscription plan and amount; currency; card metadata (brand, last four digits, expiry month/year); decline reason and code; payment-attempt history; email delivery, open, and click events; unsubscribe status; IP address of the client opening an email. |
| Special category data | None. The Service is not designed to process special categories of data under Article 9, and the Customer must not submit any. |
| Frequency of transfer | Continuous, for the duration of the Service. |
| Nature of processing | Collection, storage, structuring, retrieval, use, transmission by email, erasure. Automated generation of email copy by a large language model. No automated decision-making producing legal or similarly significant effects on data subjects. |
| Purpose of processing | Recovering failed subscription payments on the Customer's behalf: scheduling retries, sending recovery emails, hosting a card-update page, and reporting outcomes. |
| Retention period | For the duration of the account, plus a 30-day post-termination export window; backups purged within 35 days. Customer-configured retention windows may be shorter. |
| Sub-processor transfers | As set out in Annex III, for the purposes and durations stated there. |
C. Competent Supervisory Authority
The supervisory authority of the EEA Member State in which the data exporter is established or, where the exporter is not established in the EEA, the authority of the Member State in which its Article 27 representative is established, or — failing that — the authority of the Member State in which the data subjects whose personal data is transferred are located.
Annex II — Technical & Organisational Measures
Populates Annex II of the SCCs. Further detail on the Security page.
| Encryption in transit | TLS 1.2+ for all connections to the application, the database, and every sub-processor API. HSTS enforced on the public domain. |
|---|---|
| Encryption at rest | Managed-database volume encryption. Stripe access tokens and SMTP credentials additionally encrypted at the application layer with AES-256-GCM under a key held outside the database. |
| Pseudonymisation | Application logs reference internal identifiers rather than end-user email addresses where diagnosis does not require them; API request logs are anonymised after 30 days. |
| Access control | Role-based access (owner, full access, read only) enforced at the query layer; bcrypt password hashing; session cookies scoped and CSRF-protected; administrative access separated from customer accounts and logged to an immutable audit trail. |
| Tenant isolation | Every query is scoped to the authenticated account. No cross-tenant read path exists in the application. |
| Availability & resilience | Managed database with automated daily backups and point-in-time recovery; application health checks; scheduled jobs are idempotent and safe to re-run. |
| Restoration | Backup restoration is tested; recovery objectives are published on the Security page. |
| Vulnerability management | Dependency scanning, prompt patching of security advisories, and a published vulnerability disclosure channel with a safe-harbour commitment. |
| Logging & monitoring | Authentication events, administrative actions, and payment-state transitions are logged with timestamps and actor identity. |
| Data minimisation | Full card numbers are never received or stored — card data remains within Stripe's PCI-DSS Level 1 environment, and the Service operates under SAQ A scope. |
| Personnel | Least-privilege access, confidentiality obligations, and prompt revocation on role change or departure. |
| Sub-processor governance | Written data-processing terms, security review before engagement, and transfer impact assessment for transfers outside the EEA. |
Annex III — Authorised Sub-processors
Populates Annex III of the SCCs. The authoritative, continuously maintained version is at /subprocessors.
| Sub-processor | Processing | Location |
|---|---|---|
| Stripe | Payment processing, Stripe Connect authorisation, retry execution against the card networks, and platform subscription billing. | United States, Ireland |
| DigitalOcean — Managed PostgreSQL | Primary application database. Stores account records, campaign configuration, payment-attempt history, and email events. | United States (region selected at provisioning) |
| DigitalOcean Spaces | Object storage for uploaded brand logos and exported reports. | United States |
| Resend | Transactional and recovery email delivery, bounce and complaint handling, open and click event capture. | United States |
| Google Gemini (Generative Language API) | Generates personalised recovery email subject lines and body copy from campaign context. | United States |
| Google Analytics 4 | Aggregate traffic measurement on the public marketing pages only. Never loaded inside the authenticated dashboard. | United States |
| Application hosting | Runs the Next.js application server and scheduled jobs; retains web-server access logs. | United States |
Execution
This DPA is accepted by the Customer on account creation and requires no signature. Customers whose own compliance process requires a countersigned copy, a supplier-paper DPA, or completed SCC annexes on letterhead should contact us.
Payment Recovery System — Data Protection
DPA requests and signed copies: legal@paymentrecoverysystem.com
Privacy enquiries and data subject requests: privacy@paymentrecoverysystem.com
Security incidents: security@paymentrecoverysystem.com
A note on EU representation
A processor without an EU establishment that offers services to controllers in the EEA may need to designate a representative under Article 27 GDPR (and Article 27 UK GDPR for the UK). Whether it applies depends on whether the processing is occasional and on the risk profile. Confirm this with counsel before marketing to EEA or UK customers, and add the representative’s name and address to this annex once appointed.