This Data Processing Addendum (“DPA”) is an integral component and forms part of the Agreement between you (the Account Holder) and the applicable Tazapay Contracting Entity (“Tazapay”) as determined in accordance with section 2 (Definitions and Interpretation) of the General (Account Holder) Terms and Conditions, delineating the terms and conditions governing the Processing of Personal Data by Tazapay and its Affiliates in connection with the Tazapay Services.
This DPA is designed to comply with Applicable Data Protection Laws, including but not limited to the PDPA, the PIPEDA, the PDPO and such other data protection laws as may apply under the Regional Terms or in jurisdictions where Tazapay’s affiliates process Personal Data on Tazapay’s behalf. Where Regional Terms apply under section 21 of the General (Account Holder) Terms, this DPA shall be interpreted consistently with the applicable Regional Terms and the Applicable Laws of the relevant jurisdiction.
By entering into the Agreement, you affirm that you have read, comprehended and agree to be bound by the provisions of this DPA. This DPA is legally binding and applies to all Account Holders and Users who access or utilise the Tazapay Services under the Agreement.
We strongly advise you to thoroughly review this DPA, as it comprehensively outlines the terms and conditions governing the Processing of Personal Data in connection with the Tazapay Services under the Agreement. Should you have any inquiries or require further clarification regarding the Processing of Personal Data, please contact us at [email protected].
Capitalised terms not defined herein shall have the meanings assigned to them in the Agreement, including the General (Account Holder) Terms and the applicable Appendices. For definitions specific to this DPA, please refer to Appendix A (Definitions) of this DPA.
Tazapay is committed to Processing Personal Data in strict adherence to Applicable Data Protection Laws. Depending on the specific circumstances, Tazapay may function either as a Data Processor or a Data Controller, each role encompassing distinct responsibilities and purposes.
When acting as a Data Processor, Tazapay Processes Personal Data on behalf of the Account Holder (acting as the Data Controller), and strictly in accordance with the Account Holder’s documented Instructions. In this capacity, Tazapay’s Processing activities are limited to:
Platform Maintenance: Ensuring the effective operation and servicing of the Tazapay Platform, including the Tazapay Website and Dashboard.
Service Provision: Providing and facilitating access to Tazapay Services as specified in the Agreement, including Payment Gateway, Global Collection Accounts, Payouts, Escrow, Institutional Account, and any other services described in the applicable Appendices.
Transaction Processing: Processing Transactions, Payments, and related financial operations on behalf of Account Holders and their Customers.
As a Data Processor, Tazapay is committed to implementing robust security measures to safeguard Personal Data and ensure compliance with Applicable Data Protection Laws.
For the avoidance, Tazapay’s role as a Data Processor under this section 1.1 does not limit or affect Tazapay’s independent obligations as a Data Controller under section 1.2, including obligations arising under Applicable Laws that require Tazapay to independently determine the purposes and means of Processing.
In certain situations, Tazapay independently determines the purposes and methods of Processing Personal Data, thereby acting as a Data Controller. This occurs when Tazapay Processes data to meet regulatory requirements, enhance service delivery, or protect its operational integrity. Purposes of Processing as a Data Controller include:
Compliance with Legal Obligations: Tazapay Processes Personal Data to fulfil regulatory requirements, including AML screening, KYC and KYB obligations, CDD and ongoing Compliance obligations as set out in section 7 of the General (Account Holder) Terms, Sanctions screening, and responding to lawful requests from Governmental Authorities. Tazapay will not Process Sensitive Data, unless expressly required by law or with explicit consent.
Fraud Detection and Risk Management: Tazapay monitors, detects, and prevents fraudulent Transactions and activities, mitigating risks to its Account Holders, Users, Customers, and Platform, including conducting risk management and compliance reviews as described in the General (Account Holder) Terms.
Service Development: Personal Data is analysed and utilised to enhance Tazapay Services, ensuring they remain effective and relevant to Account Holder and Customer needs.
Operational Efficiency: Tazapay Processes Personal Data to support essential business operations, such as billing, invoicing, Fees, Charges, reconciliation, and customer relationship management as described in section 8 of the General (Account Holder) Terms.
Third-Party Collaboration: Tazapay engages with Service Providers, including Financial Partners, Payment Service Providers, Card Schemes, APM Providers, and other essential entities to ensure seamless service delivery. This includes data sharing as described in section 12 of the General (Account Holder) Terms and section 15 of Appendix 1 (Payment Gateway Terms).
In its role as a Data Controller, Tazapay may collaborate with its Affiliates. Each Tazapay Entity is independently responsible for its Processing activities as a separate Data Controller. Where one Tazapay entity transfers Personal Data to another for Processing, such transfer shall be governed by this DPA and appropriate intercompany arrangements.
In both roles, Tazapay adheres to stringent data protection principles, ensuring that all Processing activities are conducted lawfully, fairly, and transparently. Where the Agreement requires Tazapay to share Personal Data with third parties (including Service Providers, Card Schemes, and Payment Method Providers as described in sections 12 of the General (Account Holder) Terms, such sharing shall be conducted in accordance with this DPA and Applicable Data Protection Laws. With a focus on security, accountability and compliance, Tazapay strives to maintain the trust and confidence of its Account Holders while upholding its legal and regulatory responsibilities.
Tazapay processes Personal Data of its Account Holders, Users, Customers, and Beneficiaries strictly as necessary to deliver the Tazapay Services. The categories of Personal Data processed by Tazapay may include, but are not limited to: payment account details, bank account details, billing and shipping addresses, names, order information (such as date, time, amount, and product or service descriptions), device IDs, email addresses, IP addresses and locations, order IDs, payment card details, tax IDs and tax status, unique customer identifiers, Available Balance information, and identity information including government-issued documents (e.g., national IDs, driver’s licences, and passports).
In connection with CDD and KYC/KYB obligations under section 7 of the General (Account Holder) Terms, Tazapay may additionally process corporate registration data, beneficial ownership information, director and shareholder details, and such other information as may be required for Compliance purposes.
Tazapay limits data collection to what is required for the specified purposes and implements anonymisation or pseudonymisation wherever feasible, consistent with the Privacy Policy.
The Account Holder (as the Data Controller, where applicable) and Tazapay commit to processing Personal Data in compliance with Applicable Data Protection Laws, ensuring that all Processing activities are grounded on a valid legal basis or exception, such as consent, contractual necessity, or statutory obligation. Both parties agree to implement appropriate safeguards, such as Standard Contractual Clauses, for transfers to jurisdictions which are regarded by Applicable Data Protection Laws as not having adequate data protection to the standard required by Applicable Data Protection Laws.
The Data Controller acknowledges its responsibility to honour Data Subject requests to withdraw consent, as required by Applicable Data Protection Laws including but not limited to the PDPA.
The Account Holder (as the Data Controller, where applicable) and Tazapay commit to working collaboratively to fulfil their respective obligations under this DPA and Applicable Data Protection Laws. This cooperation extends to ensuring the exercise of Data Subjects’ rights, managing security incidents (including Data Incidents and Major Breaches), and addressing regulatory requirements. This obligation is consistent with the mutual cooperation obligations set out in section 14 of the General (Account Holder) Terms.
Each party commits to promptly notifying the other upon becoming aware of a data breach or Data Incident involving Personal Data Processed under this Agreement. The party who is the Data Controller responsible for the data breach or Data Incident shall lead the response efforts, including containment, investigation, and remediation, while the other party provides necessary assistance to mitigate adverse effects and ensure compliance with Applicable Data Protection Laws.
Specifically, Tazapay (as the Data Processor, where applicable) shall notify the Account Holder (as the Data Controller, where applicable) without undue delay of becoming aware of a data breach or Data Incident affecting Personal Data and in any event within the timeframes required under the Applicable Data Protection Laws including, but not limited to:
for breaches under subject to the PDPA, within seventy two (72) hours of completing the assessment of the breach is notifiable; and
for breaches subject to the PIPEDA, as soon as feasible after determining that the breach creates a real risk of significant harm.
The notification shall include details required under Applicable Data Protection Laws and sufficient information to allow the Account Holder to meet any obligations to inform regulatory authorities or Data Subjects.
Where a Major Breach (as defined in the General (Account Holder) Terms) occurs, both parties shall cooperate in accordance with the incident management and mutual notification obligations under section 14 of the General (Account Holder) Terms.
Both parties agree to maintain records of any data breaches and the corresponding response actions taken, in compliance with applicable legal requirements.
Tazapay (as the Data Processor, where applicable) shall Process Personal Data exclusively on documented Instructions from the Account Holder (as the Data Controller, where applicable), unless Processing is required by Applicable Laws to which Tazapay is subject, in which case Tazapay shall inform the Account Holder of that legal requirement before Processing, unless prohibited by law from doing so.
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Tazapay (as the Data Processor, where applicable) shall implement appropriate or reasonable technical and organisational measures to ensure a level of security appropriate to the risk, including, as appropriate:
The pseudonymisation and encryption of Personal Data;
The ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
The ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident;
Compliance with PCI DSS requirements where Cards are used for payment of a Transaction, as required under section 12 of the General (Account Holder) Terms and the applicable Appendix;
Measures to protect against Malware, as defined in the General (Account Holder) Terms, including virus, ransomware, denial of service attacks, and other harmful or malicious code;
a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of Processing; and
such other measures as may be required under the PDPA, PIPEDA, PDPO, or other Applicable Data Protection Laws.
To ensure compliance with data protection regulations and maintain transparency, Tazapay (as the Data Processor, where applicable) shall adhere to the following terms regarding the engagement of sub-processors:
Engagement of Sub-Processors
The Account Holder (as the Data Controller, where applicable) acknowledges that Tazapay (as the Data Processor, where applicable) is required to engage sub-processors, including Service Providers, Financial Partners, and Payment Service Providers, as necessary to perform the Tazapay Services under the Agreement. By agreeing to this DPA, the Account Holder consents to Tazapay’s use of the sub-processors listed therein and grants a general authorisation to engage additional or replacement sub-processors as required to deliver the Tazapay Services.
Sub-Processor Obligations
Tazapay (as the Data Processor, where applicable) shall enter into a written agreement with each sub-processor imposing data protection obligations comparable to those set forth in this DPA, including the implementation of appropriate or reasonable technical and organisational measures to ensure the security of Personal Data. Tazapay retains the right to periodically review sub-processor engagements to ensure compliance with its own obligations.
Sub Processor Notification and Obligations
Tazapay shall maintain an up-to-date list of Sub-processors and shall notify the Account Holder of any intended changes concerning the addition or replacement of Sub-processors, giving the Account Holder reasonable opportunity to object to such changes. If the Account Holder reasonably objects on data protection grounds, the parties shall discuss the concern in good faith. If no resolution is reached, the Account Holder may terminate the affected Tazapay Services in accordance with the Agreement.
India Sub-Processor Disclosure
The Account Holder acknowledges that Tazapay’s Affiliate in India is engaged as a Sub-Processor for operational support, technology services and compliance screening. Where Tazapay or its Affiliates engage Sub-Processors in India, Tazapay shall ensure that appropriate data protection safeguards are in place in accordance with Applicable Laws.
Tazapay (as the Data Processor, where applicable) shall notify the Account Holder (as the Data Controller, where applicable) without undue delay after becoming aware of a Data Incident in accordance with Section 3.1.3 (Incident Management) above.
At the written request of the Account Holder (as the Data Controller, where applicable), Tazapay (as the Data Processor, where applicable) shall delete or return all the Personal Data to the Account Holder after the end of the provision of the Tazapay Services relating to Processing, and delete existing copies unless Applicable Law requires storage of the Personal Data. Where required by Applicable Laws, Tazapay may retain minimal data necessary for statutory purposes beyond service termination, including data retained to satisfy Compliance obligations under section 7 of the General (Account Holder) Terms.
In the absence of a written request within ninety (90) days of the end the relevant Tazapay Service, Tazapay shall delete the Personal Data, subject to any retention required by Applicable Laws.
Tazapay shall be liable for damage caused by Processing only where it has not complied with obligations of Applicable Data Protection Laws specifically directed to Data Processors or where it has acted outside or contrary to lawful Instructions of the Account Holder. The limitations of liability set out in the General (Account Holder) Terms shall apply to this DPA.
As the entity or person determining the purposes and means of Processing Personal Data, the Account Holder (as the Data Controller, where applicable) commits to the following obligations:
The Account Holder shall ensure that all Personal Data Processing activities are conducted in compliance with Applicable Data Protection Laws. This includes establishing a valid legal basis or exception for Processing, such as obtaining necessary consents or fulfilling contractual obligations.
The Account Holder is responsible for providing clear, documented Instructions to Tazapay regarding the Processing of Personal Data. These Instructions must align with the Agreement and comply with relevant legal requirements. Any additional Processing activities beyond the original scope require a separate written agreement between the parties. Instructions may be provided through the Tazapay API, Tazapay Dashboard, or written agreements between the Account Holder and Tazapay.
The Account Holder is responsible for handling requests from Data Subjects concerning their rights under Applicable Data Protection Laws, including but not limited to access, rectification, erasure, restriction of Processing, and objection to Processing. Tazapay shall assist the Account Holder, as necessary and upon request, in fulfilling these obligations.
Where a DPIA is required under Applicable Data Protection Laws, the Account Holder shall conduct such assessment and Tazapay shall provide reasonable assistance to the Account Holder in conducting the DPIA, taking into account the nature of Processing and the information available to Tazapay.
The Account Holder shall maintain records of Processing activities carried out on its behalf by Tazapay, as required under Applicable Data Protection Laws. Tazapay shall make available to the Account Holder all information necessary to demonstrate compliance with the obligations laid down in this DPA.
In addition to the foregoing, the Account Holder shall comply with the data protection obligations set out in sections 12 and 13 of the General (Account Holder) Terms, and shall:
ensure that it has obtained all necessary consents, authorisations, and legal bases required under Applicable Data Protection Laws for the Processing of Personal Data by Tazapay;
ensure that Personal Data provided to Tazapay is accurate, complete, and up to date;
inform Tazapay without undue delay if any Personal Data provided to Tazapay is inaccurate or incomplete; and
comply with all Applicable Data Protection Laws in relation to the Personal Data it provides to Tazapay, including ensuring appropriate transparency notices are provided to Data Subjects.
As a Data Controller, Tazapay is responsible for determining the purposes and means of Processing Personal Data. In this capacity, Tazapay commits to the following obligations:
Tazapay shall Process Personal Data in strict adherence to all Applicable Data Protection Laws and regulations. This includes ensuring that all Processing activities are based on a valid legal basis or exception, such as obtaining explicit consent from Data Subjects, fulfilling contractual obligations, or complying with legal requirements.
Tazapay is committed to Processing Personal Data transparently and fairly. This involves providing Data Subjects with clear and comprehensive information about how their data is collected, used, and shared. Tazapay shall ensure that its Privacy Policy is easily accessible and written in clear, plain language, as referenced in section 12 of the General (Account Holder) Terms.
Tazapay shall respond to and facilitate the exercise of Data Subject rights under Applicable Data Protection Laws, including rights of access, rectification, erasure, restriction of Processing, data portability, and objection to Processing, in accordance with the Privacy Policy.
Tazapay shall implement appropriate or reasonable technical and organisational measures to ensure the security of Personal Data. This includes protecting data against unauthorised or unlawful Processing, accidental loss, destruction, or damage. Measures may encompass encryption, access controls, regular security assessments, and staff training on data protection principles. Where Card data is involved, Tazapay shall comply with PCI DSS as referenced in section 12 of the General (Account Holder) Terms.
Tazapay commits to collecting and Processing only the Personal Data that is necessary for the specified purposes. Tazapay shall take reasonable steps to ensure that Personal Data is accurate and, where necessary, kept up to date.
Tazapay shall maintain records of its data Processing activities and be able to demonstrate compliance with Applicable Data Protection Laws. This includes conducting DPIAs when required and cooperating with supervisory authorities.
Where the Account Holder transfers Personal Data to Tazapay across borders, the Account Holder shall ensure that such transfer complies with Applicable Data Protection Laws, including, to the extent required, by ensuring that an appropriate Data Transfer Mechanism is in place. The Account Holder is responsible for ensuring that it has obtained all necessary consents and authorisations required for the cross-border transfer of Personal Data to Tazapay.
Tazapay may transfer Personal Data across borders in connection with the Tazapay Services, including to its Affiliates and Sub-processors located in different jurisdictions. Tazapay shall ensure that any such transfer is conducted in accordance with Applicable Data Protection Laws and that appropriate safeguards are in place to protect Personal Data.
Where required by Applicable Data Protection Laws, Tazapay shall implement appropriate Data Transfer Mechanisms, including contractual clauses, binding corporate rules, or other mechanisms recognised under Applicable Data Protection Laws, to ensure that Personal Data transferred across borders receives an adequate level of protection.
In addition to the general obligations set out above, the following jurisdiction-specific requirements shall apply:
India: Where Personal Data is transferred to Tazapay’s Affiliate in India for operational processing, Tazapay shall ensure that appropriate contractual safeguard are in place, including the obligations on the affiliate to implement technical and organisational measures consistent with PDPA and PIPEDA.
Singapore: Tazapay shall ensure the recipient is bound by legally enforceable obligations as per section 26 of the PDPA.
Canada: Transfers shall comply with PIPEDA, including the requirement under Principle 1 that the transferring organisation remains accountable for Personal Data transferred to a third party for processing.
Hong Kong: Where Tazapay, acting as a Data Controller, transfers Personal Data to a third party which acts as its Data Processor, such transfers shall comply with PDPO, including the requirement that Tazapay acting as the Data Controller must adopt contractual or other means to prevent any personal data transferred to the third party from being kept longer than is necessary for processing of the data; and that Tazapay acting as the Data Controller must adopt contractual or other means to prevent unauthorized or accidental access, processing, erasure, loss or use of the data transferred to the third party for processing.
The Account Holder acknowledges that Tazapay has audit and inspection rights as set out in section 16 of the General (Account Holder) Terms. Tazapay may monitor and review the Account Holder’s Account, use of the Tazapay API, and any other information, policies, procedures, or agreements to ensure compliance with these Terms and this DPA.
At Tazapay’s written request, the Account Holder must permit and cooperate with Tazapay or its third-party auditor to audit the Account Holder’s compliance with these Terms and this DPA, consistent with section 16 of the General (Account Holder) Terms. The Account Holder agrees to preserve all relevant evidence and information and shall not intentionally withhold, conceal, destroy, or alter any record pertinent to an audit or inspection.
At the Account Holder’s written request (not more than once per calendar year), Tazapay shall make available demonstrable evidence of compliance with this DPA, which may include the summaries of third party audit reports or response to data protection questionnaires. Tazapay may redact commercially sensitive information.
Tazapay shall review this DPA and its data protection practices at least annually, updating as necessary to reflect change in Applicable Laws, regulatory guidance or processing activities.
The Account Holder understands and acknowledges that data about the Account Holder, its Users, and Customers may be disclosed to such third parties as necessary for the purpose of providing the Tazapay Services, as set out in sections 12 of the General (Account Holder) Terms. Such disclosure may be necessary for facilitating or enabling the use of Tazapay Services, compliance with Applicable Laws, or fulfilling Compliance obligations.
In connection with Appendix 1 (Payment Gateway Terms) of the Agreement, Tazapay may share data with APM Providers, Service Providers, Card Schemes, and other third parties for the purpose of managing disputes, assessing Compliance with Service Provider and Card Network Rules, and facilitating Compliance with Applicable Laws, Payment Method Rules, and Payment Method Terms.
Where Personal Data is shared with Sub-processors or Service Providers, Tazapay shall ensure that appropriate contractual and organisational safeguards are in place to protect such data in accordance with this DPA and Applicable Data Protection Laws.
To the fullest extent permitted by Applicable Laws, the Account Holder waives its right to bring any claim against Tazapay arising from Tazapay’s disclosure of information as described in sections 12 of the General (Account Holder) Terms, including any inclusion of the Account Holder or any of its Affiliates on a terminated merchant list that results from such disclosure.
The confidentiality obligations set out in section 13 of the General (Account Holder) Terms shall apply to all Personal Data Processed under this DPA. All Personal Data shall be treated as Confidential Information for the purposes of section 13 of the General (Account Holder) Terms.
Tazapay shall ensure that persons authorised to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
The confidentiality obligations in this clause shall survive the termination or expiry of this DPA and the Agreement.
In the event of any inconsistency or conflict between the provisions of this DPA and other related agreements, the following order of precedence shall apply:
Data Processing Addendum vs. the Agreement: If there is a conflict between the provisions of this DPA and the Agreement regarding the Processing of Personal Data, the provisions of this DPA shall prevail.
DPA vs. Regional Terms: Where Regional Terms under section 21 of the General (Account Holder) Terms impose additional or more stringent data protection requirements under Applicable Laws, such Regional Terms shall prevail to the extent necessary to comply with the Applicable Laws of the relevant jurisdiction.
Any dispute arising out of or in connection with this DPA shall be resolved in accordance with the dispute resolution mechanisms in the General (Account Holder) Terms, applying the governing laws and jurisdiction applicable to the Account Holder as determined under section 21 (Regional Terms) of the General (Account Holder) Terms.
“Applicable Data Protection Laws” means any and all laws, rules and regulations applicable to the relevant party relating to the Processing of Personal Data under the Agreement and this DPA, including but not limited to the PDPA, the PIPEDA and the PDPO, and any statutory instrument, order, rule, guideline or regulation made thereunder, as from time to time amended, extended, re-enacted or consolidated.
“Agreement” has the meaning given in the General (Account Holder) Terms and Conditions between the Account Holder and the applicable Tazapay Contracting Entity, as determined in accordance with section 2 (Definitions and Interpretation) of the General (Account Holder) Terms.
“Authorised Services” means services that a Governmental Authority licences, authorises, or regulates.
“Data Controller” means the entity which, alone or jointly with others, determines the purposes and means of Processing Personal Data. Where the PDPA applies to Tazapay, references to the “Data Controller” shall be read as the “organisation” that determines the purpose of Processing; where PIPEDA applies, as the organisation accountable under Principle 1; where PDPO applies, references to the “Data Controller” shall be construed as references to a data user, being a person who, either alone or jointly or in common with other persons, controls the collection, holding, processing or use of Personal Data.
“Data Incident” means an unauthorised or unlawful Processing, use, access, loss, disclosure, destruction or alteration of Personal Data in a party’s or its Affiliate’s, or a party’s or its Affiliate’s subcontractor’s, agent’s or representative’s, possession or control. Where the PDPA applies to Tazapay, “Data Incident” shall have the same meaning as “data breach” as defined under the PDPA. For the avoidance of doubt, a Major Breach (as defined in the General (Account Holder) Terms) that involves Personal Data constitutes a Data Incident.
“Data Processor” means the entity that processes Personal Data on behalf of the Data Controller. Where the PDPA applies to Tazapay, “Data Processor” shall have the same meaning as “data intermediary” as defined under the PDPA. Where the PDPO applies, references to the “Data Processor” shall be construed as references to a person that Processes Personal Data on behalf of a data user.
“Data Subject” means an identified or identifiable natural person to which Personal Data relates, including Account Holders’ Users, Customers, and Beneficiaries.
“Data Transfer Mechanism” means a transfer mechanism that enables the lawful cross-border transfer of Personal Data under Applicable Data Protection Laws, which includes transfer mechanisms that are required under Applicable Data Protection Laws in Singapore, Canada, India, and Hong Kong.
“DPIA” means a Data Protection Impact Assessment as required under Applicable Data Protection Laws.
“Instructions” or “Instruction” means any communication or documentation, including that which may be provided through a Tazapay API, Tazapay Dashboard, or written agreements between the Account Holder and Tazapay, through which the Account Holder (as the Data Controller, where applicable) instructs Tazapay (as the Data Processor, where applicable) to perform specific Processing of Personal Data for the Account Holder.
“Joint Controller” means a Data Controller that jointly determines the purposes and means of Processing Personal Data with one or more Data Controllers.
“PDPA” means the Singapore Personal Data Protection Act 2012.
“PDPO” means the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486 of the Laws of Hong Kong).
“Personal Data” means any information relating to an identifiable natural person that is Processed in connection with the Tazapay Services, and includes “personal data” as defined under the PDPA and the PDPO, “personal information” as defined under PIPEDA, and “Personal Data” as defined in section 2 (Definitions and Interpretation) of the General (Account Holder) Terms.
“PIPEDA” means the Canada Personal Information Protection and Electronic Documents Act.
“Process” means to perform any operation or set of operations on Personal Data or sets of Personal Data, such as collecting, recording, organising, structuring, storing, adapting or altering, retrieving, consulting, using, disclosing by transmission, disseminating or otherwise making available, aligning or combining, restricting, erasing or destroying, as described under Applicable Data Protection Laws. “Processes”, “Processed” and “Processing” shall be construed accordingly. Processing includes sub-processing.
“Sensitive Data” means, to the extent this data is treated distinctly as a special category of Personal Data under Applicable Data Protection Laws: (a) Personal Data that is genetic data, biometric data, data concerning health, a natural person’s sex life or sexual orientation; (b) data about racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; (c) geolocation data; or (d) sensitive personal information.
“Sub-processor” means an entity Tazapay (as a Data Processor, where applicable) engages to Process Personal Data on Tazapay’s behalf in connection with the Tazapay Services under the Agreement, and includes Service Providers (as defined in the General (Account Holder) Terms) to the extent they Process Personal Data on Tazapay’s behalf.