Bozza — in revisione legale. Questo documento non è ancora in vigore.

Note legali

Data Processing Addendum

Versione: 0.9 (draft) · Ultimo aggiornamento: 2026-09-11

Questo documento è mantenuto in inglese; fa fede il testo inglese.

1. When this applies

This addendum applies when you are a platform or marketplace and Baynoy processes personal data of your customers on your behalf (for example sub-business onboarding data you collect through us). It forms part of the Terms of Service.

2. Roles

For platform data processed on your instructions, you are the controller and AtaForge Inc. is the processor. Independently of that, we are a controller where law makes us one — verification, sanctions screening, fraud prevention and record-keeping obligations are ours and are described in the Privacy Policy.

3. Processing and instructions

We process platform data only to provide the Services and per your documented instructions, unless law requires otherwise (in which case we tell you unless the law forbids it). Subject matter, duration, nature and categories are those inherent in the Services you configured.

4. Subprocessors

You authorise the subprocessors needed to run the Services (hosting, verification, financial institutions). The current list is available on request from [email protected]; we give notice of additions and you may object on reasonable data-protection grounds.

5. Security and confidentiality

We apply the measures described on the Security page — encryption in transit and at rest, role-based and logged access, PCI-scoped card data isolation, immutable audit logging — and bind staff to confidentiality.

6. Assistance, audits, breaches

We assist you with data-subject requests and impact assessments to the extent the data is in our systems. We notify you without undue delay of a personal-data breach affecting platform data. We demonstrate compliance through documentation and, where that is insufficient, audits under reasonable conditions.

7. Transfers and deletion

International transfers use recognised safeguards (section 5 of the Privacy Policy). At termination we delete or return platform data, except what financial-services law requires us to retain — that data stays under these protections until deletion.