Data Processing Addendum
This page summarizes the Data Processing Addendum (DPA) that applies where SoniqPay processes personal data on behalf of a customer. The executable DPA is available on request and forms part of your Service Agreement.
- Agreement
- Terms of Service
- Notice
- Privacy Policy
- Notice
- Cookie Notice
- Policy
- Acceptable Use Policy
01Purpose
The DPA sets out the terms on which SoniqPay processes personal data on behalf of a customer in connection with the Services. It is designed to meet the requirements of the GDPR, the UK GDPR, and applicable US state privacy laws.
This page is a summary for convenience. The executed DPA controls.
02Roles of the parties
The customer is the controller (or "business") in respect of personal data submitted to the Services. SoniqPay is the processor (or "service provider") and processes that data only on the customer's documented instructions, including as necessary to provide, secure, and support the Services.
SoniqPay does not sell personal data, does not share it for cross-context behavioral advertising, and does not retain, use, or disclose it for any purpose other than performing the Services, except as permitted by applicable law.
03What the DPA covers
- subject matter, duration, nature, and purpose of processing;
- categories of data subjects and types of personal data;
- confidentiality obligations for personnel with access to personal data;
- security measures, described in a technical and organizational measures annex;
- sub-processing terms, including notice of changes and objection rights;
- assistance with data subject requests and with data protection impact assessments;
- personal data breach notification obligations;
- audit and information rights; and
- return and deletion of personal data at the end of the engagement.
04Sub-processing
The customer provides general authorization for SoniqPay to engage sub-processors, subject to written terms no less protective than the DPA. Our current sub-processors are listed on the Sub-processors page, and we provide advance notice of additions so customers can object on reasonable data protection grounds.
05International transfers
Where personal data is transferred out of the EEA, the UK, or Switzerland, the DPA incorporates the European Commission's Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum, together with supplementary measures as required.
06Security measures
The DPA includes an annex describing technical and organizational measures, covering access control, encryption, network security, secure development, logging and monitoring, vulnerability management, business continuity, and personnel security. Our current compliance position is described on our Security page.
07Breach notification
SoniqPay will notify the customer without undue delay after becoming aware of a personal data breach affecting the customer's personal data, and will provide the information reasonably required for the customer to meet its own notification obligations.
08Return and deletion
On termination, SoniqPay will delete or return personal data processed on the customer's behalf in accordance with the DPA, subject to retention required by applicable law.
09How to execute the DPA
Customers who require a signed DPA should contact legal@soniqpay.com. The DPA is also offered as part of the standard Service Agreement package.
Counsel should prepare the executable DPA, including the SCC module selection and the technical and organizational measures annex, before the first customer contract is signed.