PLATFORM TERMS OF USE
Last updated: July 1, 2026
INXYTECH LTD, HE 447934, Agias Zonis, 12, Agias Zonis Court,
Flat/Office 401, 3027, Limassol, Cyprus
- These Platform Terms (the "Terms") govern access to and use of the software platform, user
interface, APIs, dashboards, operational workflows and related technology tools (altogether the
“Platform”) made available by INXYTECH LTD, a company incorporated in Cyprus with
registration number HE 447934 and registered office at Agias Zonis, 12, Agias Zonis Court,
Flat/Office 401, 3027, Limassol, Cyprus (the "Platform Provider"). -
The Platform Provider is an operating technology company. The Platform Provider is not a licensed
financial institution, money services business, crypto-asset service provider, virtual asset service
provider, payment institution, custodian, broker, exchange, fiduciary or investment firm. - 1. Definitions
"Affiliate" means any entity controlling, controlled by or under common control with a person.
"Applicable Law" means any law, regulation, regulatory guidance, sanctions requirement, court or
authority order, or legally binding requirement applicable to a Party or to a Regulated Provider.
"Compliance Data" means KYB data, KYC data, Travel Rule Information, transaction data, wallet
data, KYT outputs, screening results, monitoring alerts, risk flags, documents and related information
processed through the Platform for compliance, fraud-prevention, security, regulatory or operational
purposes.
"Confidential Information" means all non-public information disclosed or made available by one
Party to the other, whether before or after the Effective Date, in connection with these Terms, the
Platform, the Platform Services or any related commercial, technical, operational, compliance or
security matter, including business information, technical information, product information, pricing,
credentials, API documentation, transaction data, Compliance Data, personal data, security
information and audit logs. - "Crypto Functionality" means platform-enabled workflows relating to crypto-asset custody access,
crypto transfers, fiat payouts, crypto payouts, conversion requests, transaction routing, Travel Rule
payloads, KYB documentation, transaction monitoring and related operational processes.
"Custodian" means a custody provider connected to the Platform, where available.
"Customer" means the legal entity that accepts these Terms and is granted access to the Platform.
"Customer Account" means the Customer profile, workspace, dashboard and access credentials
created on the Platform.
"Designated Communication Channel" or "DCC" means a Platform channel, API, message
routing layer, portal or workflow used to transmit instructions, account information, balances, Travel
Rule payloads, operational messages or other data between the Customer and a Regulated Provider.
"Effective Date" means the date on which the Customer first accepts these Terms or is granted
access to the Platform, whichever occurs first.
"Platform Services" means the SaaS and technical services described in Section 3.
"Party" means either the Platform Provider or the Customer, and "Parties" means both of them.2
"Regulated Provider" means any entity that is registered, licensed, authorised or supervised as a
money services business, crypto-asset service provider, virtual asset service provider, payment
service provider, financial intermediary, custodian, exchange, broker or similar regulated or obliged
entity and that provides Regulated Services under a separate agreement with the Customer.
"Regulated Services" means custody, crypto-asset transfer, exchange, conversion, payout, crypto
payout, payment, money transmission, brokerage, dealing, safeguarding, client-asset or other
regulated services provided by a Regulated Provider.
"Travel Rule Information" means originator, beneficiary, wallet, account, transaction, counterparty
and related information required or reasonably requested for Travel Rule compliance.
"User" means an employee, contractor, officer, administrator, authorised signatory or other person
authorised by the Customer to access the Platform.
- 2. Status of Platform and Platform Provider
2.1. The Platform is a technical and operational layer through which the Customer may access
dashboards, APIs and various tools accompanying Regulated Services.
2.2. The Platform Provider provides Platform Services as a technology and operational service
provider only. The Platform Provider does not itself provide Regulated Services.
2.3. The Customer may use the Platform to connect to Regulated Services provided by separate
Regulated Providers, where available. Such Regulated Services are provided only under
separate agreements between the Customer and the relevant Regulated Provider.
2.4. The Platform Provider is not responsible for regulatory decisions that must be made by
Regulated Providers, including onboarding approval, KYB/KYC approval, Travel Rule
determinations, transaction monitoring decisions, sanctions decisions, suspicious transaction
reporting, suspension of regulated services, safeguarding decisions, custody decisions, payout
approval or transaction rejection. -
3. Platform Services
3.1. Subject to onboarding and activation, the Platform Provider may provide the Customer with
access to the following Platform Services:
Customer Account, dashboard, API access, user management and operational workspaces;
technical routing of transaction-related messages and instructions to Regulated Providers;
technical generation, collection, validation, formatting and transmission of Travel Rule
Information;
technical collection, storage, versioning and delivery of Compliance Data and related
onboarding information;
technical transaction status tracking, balance display and reporting tools;
technical support for issuing, approving, cancelling, routing and tracking instructions to
Regulated Providers; connectivity to custody, conversion, payout, transfer and other Regulated Services provided by
connectivity to custody, conversion, payout, transfer and other Regulated Services provided by
Regulated Providers; reconciliation files, exports, audit logs, records, operational reports and notification tools;
support, incident communication, change notifications and other platform administration
services.
3.2. The specific scope, commercial terms, subscription plan, technical parameters, enabled
modules, integrations, limits, fees, billing terms, activation requirements, support arrangements
and other details of the Platform Services shall be as separately agreed between the Parties.
3.3. The Platform Provider may add, remove, suspend or modify Platform features, APIs,
integrations, workflow steps, data fields, dashboards, reports and operational tools where
required for security, legal, regulatory, technical, vendor, product or operational reasons.
- 4. Regulated Services
4.1. The Customer must enter into and maintain a separate agreement with each Regulated Provider
whose Regulated Services the Customer wishes to use. Access to the Platform does not by
itself entitle the Customer to receive any Regulated Service.
4.2. Where the Customer uses custody services provided by a Custodian, those services are
governed exclusively by the separate custody agreement between the Customer and that
Custodian. The Platform Provider is not a party to that custody agreement and has no custody
rights or obligations in respect of the Customer’s assets.
4.3. The Platform Provider may facilitate acceptance of Regulated Provider terms through the
Platform, but the relevant agreement is between the Customer and the Regulated Provider, not
between the Customer and the Platform Provider.
4.4. Each Regulated Service transaction is entered into with the Regulated Provider identified in
the relevant Platform workflow before the Customer confirms or submits the transaction. The
Platform will display, or make reasonably available, the identity of the relevant Regulated
Provider acting as the legal counterparty or service provider for that transaction. Any
transaction confirmations, receipts, invoices, statements or other transaction-specific
documents relating to Regulated Services are issued by, or on behalf of, the relevant Regulated
Provider, and not by the Platform Provider
4.5. The Platform Provider is not responsible for any refusal, delay, suspension, rejection, hold,
freeze, termination, payout failure, custody restriction, conversion price, regulatory decision or
compliance decision made by a Regulated Provider.
4.6. The Platform Provider does not recommend, promote, endorse or prefer any Regulated
Provider or Custodian and does not receive any referral fee, commission, revenue share,
success fee, kickback or other remuneration from any Regulated Provider or Custodian for the
Customer’s selection or use of that provider. The Customer independently selects each
Regulated Provider or Custodian, and access to or use of the Platform is not conditional on the
Customer selecting any particular Regulated Provider or Custodian.
- 5. Instructions
5.1. The Customer may use the Platform to create, approve, submit, transmit, cancel or track
instructions to Regulated Providers, subject to the Customer’s permissions, authentication
requirements and the applicable Regulated Provider agreement.
5.2. Any instruction transmitted through the Platform using the Customer’s credentials,
permissions, API keys, authorisation workflow or other authentication method may be treated
by the Platform Provider and the relevant Regulated Provider as an instruction of the
Customer.
5.3. The Platform Provider acts as a technical conduit and workflow processor. The Platform
Provider has no independent authority to create, approve, alter or authorise instructions in its
own name or for its own account.
5.4. Any technical generation, formatting, routing or transmission of an instruction through the
Platform shall be treated as attributable to the Customer only where it is initiated, approved or
pre-authorised by the Customer in accordance with the applicable Platform workflow,
mandate, API configuration or Regulated Provider agreement.
5.5. The Customer is solely responsible for the accuracy, completeness, authority, business purpose
and legal basis of instructions submitted through the Platform, including recipient details,
wallet addresses, asset, network, amount, payment purpose and supporting data.
- 6. Custody Connectivity
6.1. Where the Customer has a separate custody agreement with a Custodian, the Platform may
technically transmit Customer instructions to that Custodian and retrieve or display custody
account information, balances, status messages and transaction history, strictly within the
scope authorised by the Customer.
6.2. The Platform Provider may act as the DCC operator or technical proxy for Customer
instructions only where the Customer has granted a mandate under the agreement with a
Custodian, a mandate acknowledgement or another authorisation accepted by the Custodian.
6.3. The Customer remains the sole authorising source of instructions to the Custodian. The
Platform Provider does not become a party to the custody relationship and does not acquire
title to, ownership of, signing rights over, private-key access to, balance entitlement in, or
economic benefit from any assets held with the Custodian.
6.4. The Platform Provider does not hold private keys, MPC shards, seed phrases or equivalent key
material for custody wallets maintained by the Custodian. The Platform must not be treated as
a self-hosted wallet or custody account merely because the Customer accesses custody
information through it.
- 7. Customer Account, Users and Security
7.1. The Customer shall ensure that only authorised Users access the Platform. The Customer is
responsible for assigning roles, permissions, transaction limits, approval flows and access
rights to Users.
7.2. The Customer is responsible for safeguarding credentials, API keys, devices, authentication
factors, administrator accounts, internal approvals and access controls used to access the
Platform.
7.3. The Customer shall notify the Platform Provider without undue delay of any suspected
unauthorised access, credential compromise, API compromise, internal fraud, user-permission
error, security incident or incorrect instruction.
7.4. The Platform Provider may suspend or restrict access to the Platform, a User, an API key, a
workflow or an integration where required by Regulated Provider or where necessary for
security, legal, regulatory, compliance or operational reasons.
7.5. The Platform Provider may maintain logs, audit trails, authentication records, IP addresses,
timestamps, API calls, approvals, instructions, messages, document versions and acceptance
records as evidence of Platform activity. -
8. Customer Responsibilities
The Customer represents and undertakes that:
it is a legal entity acting for business purposes and has authority to enter into these Terms;
all information and documents provided through the Platform are true, accurate, complete and not misleading;
it will update information without undue delay when it changes;
it will use the Platform only for lawful business purposes and in accordance with
Applicable Law, these Terms and applicable Regulated Provider agreements;
it will not use the Platform for money laundering, terrorist financing, sanctions evasion,
fraud, tax evasion, ransomware, darknet markets, illegal gambling, weapons trafficking,
human trafficking, child exploitation or other unlawful activity;
it will obtain all licences, registrations, consents, notices and approvals required for its
own business and use of the Platform;
it will provide all notices and obtain all permissions required to upload or transmit
personal data of its directors, UBOs, employees, authorised signatories, customers,
payers, payees and counterparties through the Platform.
- 9. Availability, Changes and Support
9.1. The Platform is provided on a commercially reasonable availability basis. Specific service
levels, support hours, maintenance windows, incident response times and escalation contacts
are set out in Schedule 1.
9.2. The Platform Provider may perform scheduled or emergency maintenance and may suspend
access where required for security, legal, regulatory, vendor, network, infrastructure or
operational reasons. - 9.3. The Platform Provider is not responsible for failures, delays or unavailability caused
- by Regulated Providers, banks, payment rails, blockchain networks, cloud providers, API
providers, blockchain analytics providers, internet providers, the Customer’s systems or other
third parties outside the Platform Provider’s reasonable control.
- 10. Fees and Taxes
10.1. Platform fees, subscription fees, usage fees, implementation fees, support fees and other
charges payable to the Platform Provider shall be as separately agreed between the Parties.
10.2. Fees charged by Regulated Providers for Regulated Services are separate from Platform fees.
The Platform Provider is not responsible for fees, spreads, network fees, bank charges or other
amounts charged by Regulated Providers or third parties.
10.3. The Customer is responsible for all taxes, filings, accounting treatment and reporting arising
from its use of the Platform and Regulated Services, except for taxes imposed on the Platform
Provider’s own income.
- 11. Intellectual Property and License
11.1. The Platform Provider and its licensors retain all rights, title and interest in the Platform,
software, APIs, dashboards, documentation, workflows, rules engine, data models, templates,
reports, analytics, code, trade secrets, know-how, trademarks and other intellectual property.
11.2. Subject to these Terms and payment of applicable fees, the Platform Provider grants the
Customer a limited, non-exclusive, non-transferable, non-sublicensable, revocable right to
access and use the Platform for the Customer’s internal business operations.
11.3. The Customer shall not copy, modify, reverse engineer, decompile, scrape, resell, white-label,
sublicense, benchmark, exploit or provide third-party access to the Platform except as
expressly permitted by the Platform Provider in writing.
11.4. The Platform Provider may use aggregated, anonymised or statistical information derived from
Platform use to improve, secure and operate the Platform, provided that such information does
not identify the Customer or any individual.
- 12. Data Processing
12.1. Each Party shall comply with data protection laws applicable to it, including GDPR where
personal data is subject to GDPR and other applicable privacy laws.
12.2. The data protection roles of the Parties may vary by processing activity. Unless the Data
Processing Agreement in Schedule 2 states otherwise:
the Platform Provider acts as controller for Platform account administration, billing,
security, audit, legal claims, service analytics and its own compliance purposes;
the Customer acts as controller for personal data it uploads or submits through the
Platform;
the Platform Provider may act as processor for the Customer where it processes personal
data solely on the Customer’s instructions for Platform hosting or workflow processing.
12.3. The Customer authorises the Platform Provider to transmit personal data, Compliance Data
and Travel Rule Information to Regulated Providers, Custodian and other permitted recipients
for the purposes described in these Terms and the applicable Regulated Provider agreements.7
12.4. Where the Platform Provider processes personal data on behalf of the Customer as processor,
the Data Processing Agreement in Schedule 2 shall apply.
12.5. The Platform Provider shall not use personal data for unrelated commercial marketing or
profiling unrelated to Platform operation, compliance, fraud-prevention, security or risk-
management purposes.
12.6. The Platform Provider may retain records for the periods required by Applicable Law,
Regulated Provider agreements, audit requirements, legal claims, security obligations and
legitimate business purposes, subject to Schedule 2.
- 13. Confidentiality
13.1. Each Party shall keep the other Party’s Confidential Information confidential and use it only
for the purposes of these Terms, Platform operation, compliance, security, legal claims, audit,
support and related purposes permitted by these Terms.
13.2. Confidential Information may be disclosed to Affiliates, Regulated Providers, service
providers, professional advisers, auditors, insurers, banks, payment partners, Travel Rule
service providers, regulators, FIUs, law-enforcement bodies, courts and competent authorities
where necessary for the purposes of these Terms or required by Applicable Law, subject to
appropriate safeguards where applicable.
13.3. Confidentiality obligations survive termination for five years, except for trade secrets, security
information, personal data and legally protected information, which remain protected for as
long as required by law or their nature.
- 14. Disclaimers
14.1. THE PLATFORM AND THE PLATFORM SERVICES ARE PROVIDED ON AN “AS IS”
AND “AS AVAILABLE” BASIS. TO THE MAXIMUM EXTENT PERMITTED BY
APPLICABLE LAW, THE PLATFORM PROVIDER MAKES NO WARRANTIES,
REPRESENTATIONS OR UNDERTAKINGS, WHETHER EXPRESS, IMPLIED,
STATUTORY OR OTHERWISE, REGARDING THE UNINTERRUPTED
AVAILABILITY, ACCURACY, COMPLETENESS, FITNESS FOR A PARTICULAR
PURPOSE, MERCHANTABILITY, NON-INFRINGEMENT, PERFORMANCE,
COMPATIBILITY, SECURITY OR ERROR-FREE OPERATION OF THE PLATFORM OR
THE PLATFORM SERVICES.
14.2. The Platform Provider does not warrant that the Platform will be available without
interruption, delay, defect, cyber incident, data transmission error, integration failure, API
failure, third-party service disruption, blockchain network issue or other operational limitation.
14.3. The Platform is a technical platform. The Platform Provider does not provide legal, tax,
accounting, investment, financial, custody, payment, exchange, brokerage or regulatory advice.
14.4. The Platform Provider does not guarantee that any Regulated Provider will approve the
Customer, accept a transaction, support a particular asset or currency, execute a payout,
maintain an account, continue providing services, or make any particular regulatory or
compliance decision.8
14.5. The Platform Provider does not guarantee that any specific Regulated Provider, Regulated
Service, crypto-asset, fiat currency, payment rail, jurisdiction, recipient type, wallet type or
integration will be available at all times or at all.
14.6. The Platform Provider does not guarantee the price, execution timing, liquidity, finality,
reversibility, tax treatment or regulatory treatment of any crypto-asset, fiat payout, conversion,
transfer or Regulated Service.
14.7. Blockchain transactions may be irreversible. The Customer is responsible for verifying
addresses, networks, recipients, payment details and instructions before submission.
- 15. Liability and Limitation
15.1. Each Party is liable for direct losses caused by its breach of these Terms, wilful misconduct,
gross negligence, fraud or breach of mandatory law, subject to the limitations in these Terms
and Applicable Law.
15.2. The Platform Provider is not liable for losses arising from Regulated Provider and Custodian
decisions, rejected onboarding, rejected transactions, frozen accounts, compliance holds,
Travel Rule failures, sanctions decisions, custody losses, payout failures, conversion prices,
network failures, blockchain finality, Customer error, unauthorised use of Customer
credentials, third-party systems or force majeure, except to the extent directly caused by the
Platform Provider’s own breach of these Terms.
15.3. Neither Party is liable for indirect, special, punitive, exemplary or consequential losses, loss of
profit, loss of business, loss of opportunity, loss of goodwill, loss of anticipated savings, loss of
market appreciation or losses arising from volatility or liquidity of crypto-assets, except to the
extent such exclusion is not permitted by mandatory law.
15.4. The Platform Provider’s aggregate liability under or in connection with these Terms shall not
exceed the fees actually paid by the Customer to the Platform Provider during the twelve
months preceding the event giving rise to the claim.
15.5. Nothing in these Terms limits liability to the extent limitation is prohibited by mandatory law,
or for fraud, wilful misconduct, gross negligence, intentional breach of confidentiality,
intentional misuse of personal data, or payment obligations due and payable by the Customer.
- 16. Indemnity
16.1. The Customer shall indemnify the Platform Provider, its Affiliates, officers, employees,
contractors and service providers against direct losses, liabilities, fines, penalties, reasonable
legal costs and expenses arising from:
the Customer’s breach of these Terms or Applicable Law;
inaccurate, incomplete or misleading information submitted through the Platform;
unlawful, sanctioned, fraudulent or prohibited activity involving the Customer, its Users,
customers, payers, payees, counterparties, wallets or instructions;
third-party claims arising from Customer instructions, data or use of the Platform;
the Customer’s failure to obtain required notices, consents, authorisations, licences or
registrations.
16.2. The indemnity does not apply to the extent a claim is finally determined to have resulted from
the Platform Provider’s fraud, wilful misconduct or gross negligence.
- 17. Term, Suspension and Termination
17.1. These Terms start on the Effective Date and continue for an indefinite period unless terminated
in accordance with this Section.
17.2. Either Party may terminate these Terms on thirty days’ written notice.
17.3. The Platform Provider may suspend access or terminate immediately where the Customer
breaches these Terms, fails to pay fees, fails onboarding or ongoing due diligence, creates
legal, regulatory, AML/CFT, sanctions, security, fraud, operational or reputational risk, or
where continued access may breach Applicable Law or a Regulated Provider requirement.
17.4. Termination of these Terms does not automatically terminate separate Regulated Provider
agreements, and termination of a Regulated Provider agreement does not automatically
terminate these Terms unless the Platform can no longer be provided or continued access
creates risk.
17.5. On termination, the Customer shall stop using the Platform, pay all outstanding fees, export
available records within the period specified by the Platform Provider, and cooperate with
offboarding, data retention and security procedures.
17.6. Sections concerning definitions, fees, intellectual property, data protection, confidentiality,
liability, indemnity, records, governing law, dispute resolution and provisions intended by their
nature to survive shall survive termination.
- 18. Notices and Electronic Communications
18.1. Formal notices shall be sent by email to the address specified in the Customer Account, or to
any replacement address notified by a Party.
18.2. Operational notices may be delivered through the Platform, dashboard, API message, support
ticket, email or other electronic means. In-product notices are effective when made available
unless they state a later effective date.
18.3. The Customer agrees that electronic acceptance, click-through acceptance, API activation,
login records, timestamps and audit logs may be used as evidence of acceptance, authorisation
and instructions.
- 19. Amendments
19.1. The Platform Provider may update these Terms by giving notice through the Platform, email or
other agreed channel. Where an update materially affects the Customer’s legal rights or
obligations, the Platform Provider shall provide reasonable prior notice unless the change is
required urgently for legal, regulatory, security or operational reasons.
19.2. The Customer may terminate these Terms before the effective date of a material adverse
change, subject to payment of accrued fees and completion of offboarding steps.
19.3. Operational parameters, API specifications, supported features, providers, workflows, data
fields, documentation and technical requirements may be updated through the Platform or
documentation without formal amendment of these Terms.
- 20. Force Majeure
20.1. A Party is not liable for failure or delay caused by events beyond its reasonable control,
including natural disaster, war, terrorism, civil unrest, epidemic, pandemic, labour disruption,
utility failure, internet failure, cloud or hosting failure, blockchain network failure, fork,
protocol failure, validator failure, cyberattack, exploit, governmental action, legal change,
sanctions change, court or authority order, market infrastructure failure, vendor failure, or
failure of banking, payment, communications or Travel Rule infrastructure.
20.2. The affected Party shall use reasonable efforts to mitigate the effect of force majeure and
notify the other Party where practicable, subject to legal, regulatory and security restrictions.
- 21. General Provisions
21.1. Entire agreement. These Terms, the Schedules and any documents incorporated by reference
constitute the entire agreement between the Parties regarding Platform Services and supersede
prior discussions on the same subject.
21.2. Severability. If any provision is invalid, illegal or unenforceable, the remaining provisions
remain effective. The Parties shall replace the affected provision with a valid provision that
most closely reflects its commercial and legal purpose.
21.3. Assignment. The Customer may not assign these Terms without the Platform Provider’s prior
written consent. The Platform Provider may assign or novate these Terms to an Affiliate,
successor, acquirer or restructuring entity, provided that the assignee assumes the Platform
Provider’s obligations.
21.4. No third-party rights. Except for the Platform Provider’s Affiliates and indemnified persons
solely for enforcement of protections expressly granted to them, no person other than the
Parties has rights under these Terms.
21.5. Relationship of Parties. The Parties are independent contractors. These Terms do not create a
partnership, joint venture, agency, fiduciary, trust, employment, franchise, distribution or
regulated services relationship between the Parties.
- 22. Governing Law and Dispute Resolution
22.1. These Terms and any non-contractual obligations arising out of or in connection with them are
governed by the laws of the Republic of Cyprus.
22.2. Before commencing formal proceedings, a Party shall send a written dispute notice describing
the dispute. Senior representatives of the Parties shall seek to resolve the dispute in good faith
for thirty days after receipt of the notice.
22.3. The courts of Cyprus shall have exclusive jurisdiction over disputes arising out of or in
connection with these Terms, unless the Parties agree in writing to arbitration or another
forum.
22.4. Nothing prevents either Party from seeking interim, injunctive, conservatory or asset-
preservation relief from any competent court or authority.
- Schedule 1
Service Levels
1. Support Channels
The Platform Provider shall provide support through one of the following channels:
(a) email support;
(b) support ticket system;
(c) Platform notifications. -
2. Support Hours
Support is provided during Business Days (any day other than a Saturday, Sunday or public
holiday in the Republic of Cyprus, on which banks are generally open for business in Cyprus)
and standard business hours of the Platform Provider. -
3. Incident Severity Levels
Critical: Platform unavailability or material failure affecting production access for all or
substantially all Customers. Target initial response: 4 business hours.
High: Material degradation affecting key Platform functionality or API access. Target initial
response: 1 Business Day.
Medium: Non-critical issue affecting limited functionality or individual Users. Target initial
response: 2 Business Days.
Low: General questions, minor defects, configuration requests or documentation issues. Target
initial response: 3 Business Days. -
4. Resolution
The Platform Provider shall use commercially reasonable efforts to investigate and resolve
incidents. Response and resolution times are targets only and do not constitute guaranteed
service levels. -
5. Exclusions
Service levels do not apply to issues caused by:
(a) Customer systems, credentials, Users, API keys or incorrect configuration;
(b) Regulated Providers or other third-party systems;
(c) blockchain networks, payment rails, banks or external infrastructure;
(d) scheduled maintenance;
(e) emergency maintenance required for security, legal, regulatory or operational reasons;
(f) force majeure events; or
(g) Customer’s breach of the Terms. -
6. Maintenance
The Platform Provider may perform scheduled or emergency maintenance. Where reasonably
practicable, the Platform Provider shall provide prior notice of scheduled maintenance through
the Platform, email or another support channel.
- Schedule 2
Data Processing Agreement
This Data Processing Agreement (the "DPA") forms part of the Platform Terms and applies where
and to the extent the Platform Provider processes Customer Personal Data on behalf of the Customer
as a processor. It does not apply to personal data that a Party processes as an independent controller
for its own legal, regulatory, compliance, security, accounting, audit or business purposes. -
1. Definitions
"Controller" means the Customer, where it determines the purposes and means of processing
Customer Personal Data.
"Processor" means the Platform Provider, where it processes Customer Personal Data on behalf of
the Controller under the Platform Terms and this DPA.
"Customer Personal Data" means personal data provided, uploaded, transmitted or otherwise made
available by or on behalf of the Controller to the Processor for processing under the Platform
Services.
"Data Protection Laws" means the GDPR, UK GDPR where applicable, Cyprus data protection
law, and any other privacy or data protection law applicable to the relevant processing.
"GDPR" means Regulation (EU) 2016/679.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful
destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
"Restricted Transfer" means a transfer of Customer Personal Data to a country or recipient where
Data Protection Laws require an adequacy decision, SCCs or another lawful transfer mechanism.
"SCCs" means the Standard Contractual Clauses adopted by the European Commission for
international transfers of personal data, and any UK or Swiss addendum or equivalent transfer
mechanism where applicable.
"Subprocessor" means any processor engaged by the Processor or another Subprocessor to process
Customer Personal Data.
Capitalised terms not defined in this DPA have the meaning given to them in the Platform Terms.
- 2. Roles and Scope
The Parties acknowledge that, for the processing covered by this DPA, the Customer acts as
Controller and the Platform Provider acts as Processor.
The Processor shall process Customer Personal Data only for the purposes described in this DPA, the
Platform Terms and documented instructions of the Controller, unless required to do otherwise by
applicable law. In that case, the Processor shall inform the Controller of that legal requirement before
processing, unless legally prohibited from doing so.
- 3. Details of Processing
The subject matter, duration, nature, purpose, categories of personal data and categories of data
subjects are set out in Annex 1 to this DPA.
- 4. Processor Obligations
The Processor shall process Customer Personal Data only on documented instructions from the
Controller, including instructions contained in the Platform Terms, this DPA and configuration
settings used by the Controller in the Platform.
The Processor shall ensure that persons authorised to process Customer Personal Data are subject to
appropriate confidentiality obligations.
The Processor shall not sell Customer Personal Data or use Customer Personal Data for its own
unrelated commercial purposes, marketing or profiling, except where the Platform Terms expressly
permit independent-controller processing by the relevant Party.
Taking into account the nature of the processing, the Processor shall provide reasonable assistance to
the Controller to respond to data subject requests, fulfil security obligations, conduct data protection
impact assessments and consult supervisory authorities where required by Data Protection Laws.
- 5. Subprocessors
The Controller grants the Processor general authorisation to engage Subprocessors to support the
Platform Services.
The Processor shall maintain a list of Subprocessors and make it available to the Controller upon
request or through the Platform, documentation or other reasonable channel.
The Processor shall impose on each Subprocessor data protection obligations that are no less
protective than those imposed on the Processor under this DPA, to the extent applicable to the nature
of the services provided by that Subprocessor.
The Processor remains responsible to the Controller for the performance of the Subprocessors’
obligations concerning Customer Personal Data.
- 6. International Transfers
The Processor shall not make a Restricted Transfer unless an appropriate lawful transfer mechanism
is in place, including an adequacy decision, SCCs, binding corporate rules or another mechanism
permitted by Data Protection Laws.
Where the Processor engages a Subprocessor located in, or processing Customer Personal Data from,
a third country that is not subject to an applicable adequacy decision and the engagement involves a
Restricted Transfer, the Processor shall enter into SCCs or equivalent transfer mechanism with that
Subprocessor before the Subprocessor processes Customer Personal Data.
- 7. Personal Data Breach
The Processor shall notify the Controller without undue delay after becoming aware of a Personal
Data Breach affecting Customer Personal Data.
The notification shall include, to the extent available, a description of the nature of the breach, the
categories and approximate number of data subjects and records concerned, likely consequences,
measures taken or proposed to address the breach, and contact details for follow-up.
The Processor shall take reasonable steps to contain, investigate and remediate the Personal Data
Breach and shall provide reasonable cooperation to the Controller in meeting any notification
obligations under Data Protection Laws.
- 8. Security
The Processor shall implement and maintain technical and organisational measures appropriate to the
risk, taking into account the nature, scope, context and purposes of processing. The minimum
security measures are set out in Annex 2 and may be updated from time to time provided that the
overall level of protection is not materially reduced.
- 9. Compliance Information
The Processor shall make available information reasonably necessary to demonstrate compliance
with this DPA, including security summaries, certifications, audit reports, policies, technical
documentation or written responses, subject to confidentiality, security and third-party restrictions.
- 10. Return and Deletion
Upon termination or expiry of the Platform Services, the Processor shall, at the Controller’s choice,
delete or return Customer Personal Data, unless continued retention is required by applicable law,
security, backup, dispute-resolution, audit or legitimate compliance requirements.
Backups and archival copies may be retained for a limited period in accordance with the Processor’s
standard retention and deletion cycles, provided that they remain protected and are not actively
processed except for restoration, security, legal or compliance purposes.
- 11. Order of Precedence
In case of conflict between this DPA and the Platform Terms, this DPA prevails with respect to
processing of Customer Personal Data by the Processor on behalf of the Controller.
- ANNEX 1
DETAILS OF PROCESSING
Subject matter: Provision of Platform Services.
Duration: For as long as the Platform Terms remain in effect, plus any retention period required or
permitted under the Platform Terms, this DPA or applicable law.
Nature of processing: Collection, upload, receipt, hosting, storage, organisation, structuring, access,
retrieval, transmission, validation, formatting, disclosure by transmission, logging, deletion and other
processing necessary to provide the Platform Services.
Purposes: Provision, maintenance, support and security of the Platform Services; audit logging;
troubleshooting; support; incident response; and related operational purposes.
Categories of data subjects: Customer representatives, officers, directors, beneficial owners,
authorised signatories, employees, contractors, Users, payers, payees, counterparties, end users and
other persons whose data is submitted through the Platform by or on behalf of the Customer.
Categories of personal data: Any personal data submitted through the Platform.
Special categories / sensitive data: Not intentionally requested by the Processor. The Customer shall
not submit special categories of personal data.
Processing frequency: Continuous.
- ANNEX 2
TECHNICAL AND ORGANISATIONAL MEASURES
The Processor shall implement and maintain technical and organisational measures appropriate to the
nature, scope, context and risk of the processing, including the following measures where applicable
to the Platform Services.
Access control
Role-based access, least-privilege access, authentication controls, user permission management and
access review procedures.
Encryption and transmission security
Encryption in transit where appropriate, secure API communication, protected credentials and secure
transmission channels.
System security
Logging, monitoring, vulnerability management, patching, malware protection, secure configuration
and network security controls appropriate to the Platform Services.
Data segregation
Logical segregation of Customer environments, accounts, workspaces, records or data sets as
appropriate to the Platform architecture.
Availability and resilience
Backup, recovery, business continuity, incident response and continuity procedures appropriate to the
Platform Services.
Personnel controls
Confidentiality obligations, security awareness, access restrictions and internal policies for personnel
with access to Customer Personal Data.
Incident management
Procedures for detection, investigation, escalation, containment, remediation and notification of
security incidents and Personal Data Breaches.
Subprocessor management
Due diligence, contractual data protection obligations, security review and monitoring of
Subprocessors proportionate to processing risk.
Deletion and retention
Retention controls, deletion procedures, backup retention cycles and secure disposal processes as
applicable.