Skip to content

Legal

Templates for how Paycux plans to handle customer data, contracts and support commitments. Everything here is a working draft.

Template — under legal review. This document is not yet in force. It is a working draft, has not been signed by Paycux, and should not be relied on for a real engagement until a dated, executed version is published.

Data processing addendum

Last updated: August 31, 2026 · Draft, not yet in force

This Data Processing Addendum (“Addendum”) is drafted to form part of the Terms of Service (“Agreement”) between a Subscriber and Paycux. It describes how Paycux would process personal data on Subscriber’s behalf, in line with data protection law such as the GDPR and, where applicable, KVKK. Capitalised terms not defined here have the meaning given in the Agreement.

1. Subject matter and duration

This Addendum reflects the parties’ commitment to applicable data protection law regarding Paycux’s processing of Subscriber Personal Data under the Agreement. It becomes effective when the Agreement does, and Paycux would process Subscriber Personal Data until the relationship ends.

2. Definitions

  • Subscriber Personal Data means Subscriber Data that is personal data processed by Paycux on Subscriber’s behalf.
  • Data Protection Laws means the privacy, data protection and cybersecurity laws that apply to Subscriber Personal Data, including the GDPR and, where applicable, KVKK.
  • Security Incident means a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Subscriber Personal Data, attributable to Paycux.
  • Subprocessor means a vendor or third-party service provider authorised by Paycux to process Subscriber Personal Data — see the subprocessors page.

3. Data use and processing

Documented instructions

Paycux would process Subscriber Personal Data to provide the Service, in line with the Agreement, this Addendum, and any further written instructions from Subscriber. If an instruction appears to conflict with applicable law, Paycux would flag that before proceeding, unless legally prohibited from doing so.

Subprocessors

Subscriber authorises Paycux to engage the Subprocessors needed to deliver the Service. Paycux would hold each Subprocessor to data protection terms consistent with this Addendum, and remain responsible for their performance. Before adding a new Subprocessor, Paycux intends to give at least ten (10) business days’ notice by updating the subprocessors page, so Subscriber can object on reasonable data-protection grounds within that window.

Confidentiality and data subject requests

Anyone authorised to process Subscriber Personal Data would be bound by confidentiality. Where required by law, Paycux would give reasonable assistance with data subject requests and, where applicable, data protection impact assessments relating to the Service.

4. Information security program

Paycux would maintain administrative, technical and physical safeguards designed to protect Subscriber Personal Data, aligned with industry-standard practice for the sensitivity of the data involved. That includes access controls limited to staff and Subprocessors with a genuine need, logical separation between customers’ data, and encryption in transit and, where appropriate, at rest. Formal third-party certification of this program is not yet in place (planned).

5. Security incident notification

On becoming aware of a Security Incident, Paycux would notify Subscriber without undue delay and within the timeframe required by applicable law, including the details needed for Subscriber to meet its own notification obligations, to the extent that information is available.

6. Cross-border transfers

Where Subscriber Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country without an adequacy decision, the parties intend for that transfer to be governed by an appropriate mechanism such as the EU Standard Contractual Clauses, attached as an appendix once the Agreement is executed. The same principle applies to transfers out of Turkey under KVKK, using the mechanism KVKK requires at the time.

7. Audits

Where Data Protection Laws give Subscriber an audit right, Subscriber may exercise it by having Paycux complete a data protection questionnaire of reasonable length, at most once per year, subject to reasonable confidentiality procedures.

8. Data deletion

On expiry or termination of the Agreement, Paycux would delete Subscriber Personal Data, except for backup or archival copies handled under Paycux’s normal retention schedule, or data Paycux must keep under applicable law — which would be isolated from further processing.

9. Processing details

DetailDescription
Subject matterProcessing needed to provide the Service under the Agreement.
DurationUntil expiry or termination of the Agreement.
Categories of data subjectsSubscriber's authorised users and, where applicable, their App End-Users.
Nature and purposeHosting, authentication, storage and support of the Service.
Categories of dataAccount and profile data submitted by Subscriber through the Service.

Appendix

A completed appendix — covering the applicable transfer mechanism and any exhibit-level security detail — would be attached once this Addendum is signed. Contact legal@paycux.com to request the current draft.