Legal

Data Processing Addendum

For enterprise customers. Draft — final version is countersigned with your order form.

This DPA governs our processing of personal data on your behalf. Request the full version at legal@merchant.bd.

Scope

Applies when you are the controller and we are the processor of personal data relating to your merchants or end customers.

Security measures

See Security. Measures include encryption in transit and at rest, RLS, audit logging, and access restrictions.

Sub-processors

Hosting and observability sub-processors are listed on request. We notify you of changes with 30 days advance notice.

Breach notification

We notify you within 72 hours of confirming a personal-data breach impacting your data.

Audit rights

You may audit our compliance annually, on 30 days notice, subject to confidentiality.