All legal documents

Data Processing Agreement

Effective: [EFFECTIVE DATE] · Version 1.0

This DPA forms part of the Terms of Service between [COMPANY LEGAL NAME] ("Processor", "we") and the merchant ("Controller", "you"). It applies whenever we process personal data of payers on your behalf.

It does not cover data where we act as controller in our own right — your account data, our verification of you, and our fraud and anti-money-laundering monitoring. Those are governed by the Privacy Policy, and we cannot accept your instructions about them, because we process that data to meet our own legal obligations.


1. Roles

  • You are the controller of payer personal data. You decide why it is collected and what it is used for.
  • We are the processor. We act on your documented instructions.
  • Where we determine purposes ourselves — fraud prevention, AML/CFT, meeting our own legal obligations, and improving the security of the platform — we act as an independent controller for that narrow purpose. Applicable law requires this and it is not something either of us can contract away.

2. Subject matter and duration

We process payer personal data for as long as you have an account, plus any retention period required by law (see §9).

3. Nature and purpose of processing

To provide payment services: initiating collections and payouts, routing transactions to mobile-money providers, maintaining your wallet and transaction history, sending you webhooks, and giving you dashboard and API access to your own records.

4. Categories of data subject

  • Payers who make payments to you through SP-Heavy
  • Recipients of payouts you initiate

5. Types of personal data

  • Mobile-money number (MSISDN)
  • Transaction amount, currency, status and timestamps
  • Transaction references, including the provider's own reference
  • Any metadata you attach — for example an order ID or customer reference
  • Technical data such as IP address, used for fraud prevention and security

You control what you put in metadata. Do not send us special-category data (health, religion, political opinions, biometrics), government identity numbers, or payment-card details. Our metadata field is not designed for it, and doing so puts you in breach of this DPA.

6. Our obligations

We will:

  1. Process payer data only on your documented instructions, unless required otherwise by law — in which case we will tell you, unless the law forbids it.
  2. Ensure people authorised to process the data are bound by confidentiality.
  3. Implement appropriate technical and organisational security measures — see §7.
  4. Respect the conditions in §8 for engaging sub-processors.
  5. Assist you, so far as reasonably possible, in responding to data-subject requests.
  6. Assist you with security, breach notification, and impact assessments, taking into account what we know and can access.
  7. On termination, delete or return payer data, except where law requires us to keep it (§9).
  8. Make available the information reasonably needed to demonstrate compliance, and allow audits under §10.

7. Security measures

We maintain, at minimum:

  • Encryption in transit — TLS on all API, dashboard and webhook traffic
  • Credential protection — passwords stored as salted scrypt hashes; API secret keys stored as peppered hashes and never in plaintext; two-factor secrets encrypted with AES-256-GCM at rest
  • Session security — short-lived access tokens with rotating, revocable refresh sessions, and revocation of all sessions on credential change
  • Access control — role-based access limiting staff to what their role requires
  • Abuse controls — rate limiting, per-account lockout, and constant-time credential comparison
  • Integrity — an append-only double-entry ledger, so financial history is auditable and tamper-evident
  • Authenticated webhooks — HMAC-SHA256 signatures with replay protection, so you can verify messages genuinely came from us
  • Audit logging of security-relevant events
  • Backups, with restoration tested [FREQUENCY]

We may change specific measures, but not in a way that materially reduces security.

8. Sub-processors

  1. You give general authorisation for us to engage sub-processors.
  2. The current list is at Sub-processors.
  3. We will give at least `[NOTICE PERIOD — e.g. 30]` days' notice before adding or replacing one. [Describe the notification channel — e.g. email to the account address, or a subscribable page.]
  4. You may object on reasonable data-protection grounds within that period. If we cannot resolve your objection, you may terminate the affected service without penalty.
  5. We impose data-protection obligations on each sub-processor equivalent to those in this DPA, and we remain fully liable to you for their performance.

Note: mobile-money providers (MTN, Orange) and settlement banks are not sub-processors in the ordinary sense — they are independent controllers acting under their own regulatory obligations. We cannot bind them to our instructions, and a payment cannot be made without sending them the payer's number.

9. Retention and deletion

  1. On termination, we delete or return payer data within [e.g. 90 days], at your choice.
  2. Except where we must keep it — transaction records, ledger entries and supporting data are retained under anti-money-laundering and accounting law for [RETENTION PERIOD], typically at least ten years.
  3. Retained data stays subject to this DPA's confidentiality and security obligations.
  4. Backups are deleted on their ordinary rotation cycle.

You cannot instruct us to delete data we are legally required to retain. If you receive an erasure request covering such data, we will help you explain the position to the data subject.

10. Audit

  1. We will provide information reasonably necessary to demonstrate compliance.
  2. You may audit no more than once every 12 months, on [e.g. 30] days' written notice, during business hours, without unreasonably disrupting our operations, and subject to confidentiality.
  3. More frequent audits are permitted following a personal-data breach affecting your data, or where a regulator requires it.
  4. Where we hold a relevant third-party certification or report, providing it satisfies §10.1.
  5. You bear your own audit costs, and our reasonable costs where an audit exceeds §10.1.

11. Personal data breaches

  1. We will notify you without undue delay, and in any event within [e.g. 48 hours] of becoming aware of a breach affecting payer data you control.
  2. The notification will describe, so far as known: the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed.
  3. Where we cannot provide all of it at once, we will provide it in phases without undue further delay.
  4. You are responsible for notifying the supervisory authority and affected data subjects where your law requires it — you are the controller. We will give you the information you reasonably need to do so.

12. International transfers

Some sub-processors may process data outside Cameroon and the CEMAC region. Where that occurs we ensure an appropriate transfer mechanism is in place. The Sub-processors list identifies location for each.

[Confirm with counsel the transfer mechanism valid under Cameroonian law, and whether standard contractual clauses are needed for any EU-origin data.]

13. Data-subject requests

  1. If a payer contacts us directly about data we process for you, we will not respond substantively. We will tell them to contact you, and forward the request.
  2. We will assist you in responding, taking into account the nature of the processing and what we can access.
  3. Where our assistance goes materially beyond routine effort, we may charge our reasonable costs, agreed in advance.

14. Liability

Liability under this DPA is subject to the limits in the Terms of Service §15, except where applicable data-protection law does not permit those limits to apply.

15. Conflict

If this DPA conflicts with the Terms of Service on the processing of payer personal data, this DPA prevails.


Annex A — Processing summary

Subject matterProvision of payment processing services
DurationTerm of the merchant relationship, plus legal retention
Nature and purposeInitiating and settling mobile-money collections and payouts; transaction records; notifications
Personal dataMSISDN, transaction amount/status/references, merchant-supplied metadata, technical data
Data subjectsPayers and payout recipients
Special categoriesNone — you must not submit any

[COMPANY LEGAL NAME] · Data protection: [PRIVACY EMAIL]