Legal
Data Processing Addendum
Provided to merchants at production onboarding.
Last updated: 29 July 2026
This page is the platform Data Processing Addendum template. It is a template, not a signed contract: execution requires countersignature, and the jurisdiction-specific annexes attached to the signable copy (Standard Contractual Clauses, UK Addendum) form part of the executed addendum.
1. Parties and roles
This Data Processing Addendum (the Addendum) is entered into between MNVA Pay EDPK, a company incorporated in Bulgaria (Moneva), and the merchant identified in the signable copy (the Merchant). It forms part of the Terms of Service or of the signed services agreement between the parties (together, the Agreement).
- The Merchant is the controller. The Merchant's end customers are the Merchant's customers: the Merchant determines why and how their personal data is processed.
- Moneva is the processor. Moneva processes that data only to provide the platform services the Merchant instructs through the API and dashboard, on the terms of this Addendum.
- Limited independent-controller role. Moneva acts as an independent controller only for the records it must retain under Clause 11 (legal and financial-crime record-keeping) and for its own administration of the Merchant's account.
2. Definitions
- GDPR means Regulation (EU) 2016/679 and includes the UK GDPR where it applies. Controller, processor, personal data, processing, data subject and personal data breach have the meanings given in Article 4 GDPR.
- Merchant Personal Data means personal data of the Merchant's end customers, their representatives, and payout beneficiaries that Moneva processes on the Merchant's behalf under the Agreement.
- Subprocessor means a processor engaged by Moneva to process Merchant Personal Data.
- SCCs means the standard contractual clauses adopted by the European Commission under Article 46(2)(c) GDPR; UK Addendum means the UK Information Commissioner's international data transfer addendum to the SCCs.
3. Subject matter, duration, nature and purposes
- Subject matter. Customer onboarding including identity-verification relay (KYC and KYB), virtual account issuance, beneficiary management, payout execution, and related status reporting and support.
- Duration. The term of the Agreement, plus the wind-down period until deletion or return under Clause 11 is complete.
- Nature and purposes. Collection, recording, storage, retrieval, transmission and erasure of Merchant Personal Data as needed to provide the services the Merchant instructs. Full processing details are set out in Annex I and frozen in the signable copy at execution.
4. Documented instructions
The Agreement, this Addendum, and the Merchant's API calls and dashboard actions are the Merchant's documented instructions, including with regard to transfers of personal data to a third country or an international organisation. Moneva processes Merchant Personal Data only on those instructions, unless Union or Member State law to which Moneva is subject requires otherwise; in that case Moneva informs the Merchant of the requirement before processing, unless that law prohibits it on important grounds of public interest.
Moneva informs the Merchant immediately if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
5. Confidentiality
Moneva ensures that every person authorised to process Merchant Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality. Access is limited to personnel who need it to provide the services.
6. Security
Moneva implements and maintains the technical and organisational measures required by Article 32 GDPR, appropriate to the risk of the processing. The core of that programme is described in Annex II. Moneva may update the measures during the term, provided protection does not fall below the level committed at execution. A fuller description of the measures is available to contracted merchants on written request to ops@moneva.io.
7. Subprocessing
- General authorisation. The Merchant grants a general written authorisation for Moneva to engage the subprocessor categories listed in Annex III for the purposes stated there.
- Named register. The named subprocessor register is provided at execution and thereafter on written request to ops@moneva.io. It is Confidential Information under the Agreement.
- Changes are announced. Moneva notifies the Merchant's account contact directly, by name, under the Agreement's confidentiality terms, before an added or replacement subprocessor processes Merchant Personal Data; the affected category is reflected in the categories published in the Privacy Policy. The Merchant may object on reasonable data-protection grounds. If no workable alternative exists, the Merchant may terminate the affected service.
- Obligations flow down. Every subprocessor is bound in writing to data-protection obligations no weaker than this Addendum, and Moneva remains fully liable to the Merchant for the subprocessor's performance.
- Partners are not subprocessors. Licensed payout, banking and identity-verification partners are independent controllers, or processors of those partners, for the personal data they process to meet their own regulatory obligations, including KYC, AML and sanctions screening. Moneva discloses data to them as part of the instructed services, not as subprocessing.
8. International transfers
- Moneva transfers Merchant Personal Data to a third country or an international organisation only on the Merchant's documented instructions or where required by Union or Member State law, and only with the safeguards required by Chapter V GDPR: an adequacy decision, the SCCs, or another valid transfer mechanism.
- Where the Merchant is established in a third country without an adequacy decision, the applicable SCCs are attached to the signable copy. Where the UK GDPR applies to a transfer and requires it, the UK Addendum is attached. Annexes attached to the signable copy form part of the executed Addendum and prevail over it to the extent of any conflict.
- Annex III states the processing location of each subprocessor category.
9. Data subject rights
Taking into account the nature of the processing, Moneva assists the Merchant by appropriate technical and organisational measures in responding to data subject requests under Chapter III GDPR: access, rectification, erasure, restriction, portability and objection. Erasure and export are served through the API's data subject rights endpoints; requests without an endpoint are handled via ops@moneva.io.
If a data subject contacts Moneva directly, Moneva forwards the request to the Merchant without undue delay and does not respond on the merits unless the Merchant instructs it or the law requires it.
10. Assistance with security, breaches and impact assessments
- Articles 32 to 36. Taking into account the nature of the processing and the information available to it, Moneva assists the Merchant in ensuring compliance with Articles 32 to 36 GDPR: security, breach notification, data protection impact assessments and prior consultation.
- Breach notice. Moneva notifies the Merchant without undue delay, and at the latest 72 hours after becoming aware of a personal data breach affecting Merchant Personal Data, with the known facts, the likely consequences, and the measures taken or proposed, then keeps the Merchant updated as the investigation proceeds. Notice is not an admission of fault.
11. Deletion and return
- During the term. Erasure and portability requests from end customers are served through the API's data subject rights endpoints.
- Export window. After termination of the Agreement, and at the Merchant's choice, Moneva returns or deletes Merchant Personal Data. For thirty days after termination Moneva makes the data available for export through the API, as per-customer JSON export, consistent with the Terms of Service.
- Retention carve-out. After the export window Moneva deletes or anonymises Merchant Personal Data, except records it must keep to comply with Union or Member State law or to meet the financial-crime record-keeping duties owed to its licensed partners. Moneva holds those retained records as an independent controller, keeps only what the duty requires, retains them only for the periods in Annex I, and continues to protect them with measures no weaker than Annex II.
12. Audit and information rights
- Information first. Moneva makes available the information necessary to demonstrate compliance with Article 28 GDPR, including answers to reasonable security questionnaires and available summaries of third-party attestations and test results.
- Audits with notice. Where that information is not sufficient, the Merchant or an auditor it mandates, not a competitor of Moneva, may audit the relevant processing on thirty days' written notice, at most once in any twelve-month period and at the Merchant's cost, unless a personal data breach affecting Merchant Personal Data or a supervisory authority requires more.
- Boundaries. Audits run during business hours, under confidentiality, with reasonable measures to avoid disruption. They give no access to other customers' data or to the systems of Moneva's licensed partners or other third parties; for those, Moneva provides available attestations instead.
13. Liability
Liability under this Addendum, including under the SCCs where they apply between the parties, is subject to the exclusions, the aggregate liability cap and the mandatory carve-outs in Sections 20 through 22 of the Terms of Service, or the corresponding provisions of a signed services agreement. The cap applies once, across the Agreement and this Addendum together, not separately for each. Nothing in this clause limits the rights of data subjects or of supervisory authorities, or either party's liability where the GDPR does not permit it to be limited.
14. Term, precedence and governing law
- Term. This Addendum takes effect on execution and remains in force for as long as Moneva processes Merchant Personal Data under the Agreement, and thereafter until deletion or return under Clause 11 is complete.
- Precedence. For the processing of personal data, this Addendum prevails over conflicting terms of the Agreement, and the SCCs prevail over this Addendum where they apply.
- Governing law. This Addendum is governed by the same law and jurisdiction as the Agreement: under the Terms of Service, the laws of Bulgaria and the courts of Sofia, except where the SCCs mandatorily require otherwise.
15. Execution
- Countersignature. This page is the template; it binds nobody on its own. Execution requires countersignature of the signable copy, which identifies the Merchant and is exchanged during production onboarding via ops@moneva.io.
- Annexes frozen at execution. The version presented at execution, together with the annexes attached to the signable copy (Annexes I to III and, where required, the SCCs and UK Addendum), is preserved and forms the executed addendum. Later changes to this template do not amend an executed addendum; amendments require the parties' agreement in writing, which includes electronic form.
- Timing. Production access is enabled once the Addendum is in force. Sandbox testing with synthetic data needs no addendum.
Annex I: Processing details
- Data subjects. The Merchant's end customers, contact persons and representatives of the Merchant's business customers, and payout beneficiaries.
- Categories of personal data. Identity and contact data (name, email address, country, date of birth, residential address, phone number), beneficiary bank details, transfer records (amounts, currencies, status, timestamps, customer and beneficiary references, fee records), wallet and settlement addresses, and related support correspondence.
- Special categories. None. The services are not designed for special categories of personal data (Article 9 GDPR) or for data relating to criminal convictions and offences (Article 10 GDPR), and the Merchant instructs that none be submitted.
- Frequency. Continuous, for the duration of the Agreement.
- Nature and purposes. As set out in Clause 3: onboarding including identity-verification relay, virtual account issuance, beneficiary management, payout execution, status reporting and support.
| Record | Retention |
|---|---|
| Transfers and fee records | Five years after the customer relationship ends (financial-crime record-keeping) |
| End-customer identity and contact data | Until an erasure request, or account close plus 90 days |
| API request logs (path, status, timing, request id; never bodies or keys) | 30 days |
Erasure anonymises the personal data and keeps the financial record where a retention duty overrides the right to erasure (Article 17(3) GDPR).
Annex II: Technical and organisational measures
- Encryption in transit. TLS for all data in transit.
- Encryption at rest. Stored records are encrypted at rest; API keys are never stored in plaintext.
- Access control. Administrative access is restricted to authorised personnel on a need-to-know basis, with role-based access to identity data.
- Audit trail. Staff actions on customer records, including every view of identity data, are recorded.
- EU hosting. Primary data store and compute run in the EU.
- Confidentiality. Authorised persons are bound as described in Clause 5.
- Further detail. A fuller description of the measures is available to contracted merchants on written request to ops@moneva.io.
Annex III: Subprocessor categories
The Merchant's general authorisation under Clause 7 covers these categories. Cloudflare is the one subprocessor named publicly; the named register behind each category is provided at execution and on written request to ops@moneva.io, as Confidential Information under the Agreement.
| Category | Purpose | Location |
|---|---|---|
| Cloud database provider | Primary data store, encrypted at rest | EU |
| Cloud compute provider | Compute and hosting | EU |
| Cloudflare | Network edge: TLS termination, DDoS protection | Global edge network |
| Transactional email provider | Status and sign-in email delivery | EU |
| Error-monitoring provider | Error monitoring; personal data scrubbed before send | US |
Licensed payout and banking partners, and the identity verification provider they engage, are not subprocessors: they process personal data as independent controllers, or as processors of those partners, under their own regulatory obligations. They are listed for transparency in the Privacy Policy.