1Introduction
This Data Processing Policy (the "Data Terms") forms part of the contractual relationship between EXICASH SDN BHD (Registration No. 202601015752 (1677849-M)), 16-19, Menara Mutiara Sentral, No. 2, Jalan Desa Aman 1, Cheras Business Centre, 56000 Kuala Lumpur, Malaysia (the "Provider", "EXICASH", "we", "us" or "our") and the company, business or other legal entity that registers for, is approved for, or uses the Services (the "Merchant", "you" or "your").
2SCOPE
1.1 Application
These Data Terms apply to the Processing of Personal Data by either Party in connection with:
- registration and onboarding of the Merchant;
- operation of the Merchant Account;
- payment acceptance;
- Payouts;
- Refunds and Chargebacks;
- Transaction routing and processing;
- reconciliation and reporting;
- merchant support;
- fraud, risk and security management;
- compliance and regulatory activities;
- operation and administration of the Platform; and
- other Services provided under the TOS.
1.2 Relationship with TOS
These Data Terms form part of the agreement between the Provider and the Merchant.
Terms defined in the TOS have the same meaning in these Data Terms unless expressly stated otherwise.
1.3 Priority
If there is any inconsistency between these Data Terms and the TOS concerning the Processing, protection, security, retention, transfer or handling of Personal Data, these Data Terms shall prevail to the extent of that inconsistency.
For all other matters, the TOS shall prevail.
3DEFINITIONS
In these Data Terms:
“Applicable Data Protection Law” means the Personal Data Protection Act 2010 of Malaysia, as amended from time to time, together with regulations, standards, binding requirements, orders and other Applicable Law concerning privacy or Personal Data applicable to the relevant Processing.
“Data Controller” means a person that processes Personal Data, has control over or authorises the Processing of Personal Data, or otherwise falls within the corresponding concept under Applicable Data Protection Law.
“Data Processor” means a person that Processes Personal Data on behalf of a Data Controller or otherwise falls within the corresponding concept under Applicable Data Protection Law.
“Data Subject” means an identified or identifiable individual to whom Personal Data relates.
“Personal Data” has the meaning given under Applicable Data Protection Law.
“Personal Data Breach” means any breach of Personal Data as defined by Applicable Data Protection Law, including any unauthorised or accidental access, collection, use, disclosure, alteration, loss, destruction or other compromise of Personal Data.
“Process”, “Processed” and “Processing” include any operation performed on Personal Data, whether by automated or non-automated means, including collection, recording, organisation, storage, access, retrieval, consultation, use, transmission, disclosure, matching, analysis, restriction, deletion, destruction or anonymisation.
“Sub-processor” means a third party appointed by the Provider to Process Personal Data on behalf of the Merchant where the Provider is acting as a Data Processor.
4ROLES OF THE PARTIES
3.1 Roles Depend on the Processing Activity
The Parties acknowledge that their respective roles may vary depending on the relevant Processing activity.
A Party may act as a Data Controller for certain Processing and as a Data Processor for other Processing.
Nothing in these Data Terms shall designate a Party as a Data Processor where, under Applicable Data Protection Law and having regard to the relevant Processing activity, that Party acts as a Data Controller.
3.2 Provider as Data Controller
The Provider may act as an independent Data Controller in relation to Personal Data that it determines is reasonably necessary to Process for its own legitimate legal, regulatory, security and business responsibilities in connection with the Services, including:
- Merchant registration and administration;
- identity and business verification;
- due diligence and Know-Your-Customer or equivalent verification;
- beneficial ownership verification;
- sanctions and financial-crime screening;
- fraud prevention and investigation;
- Platform and account security;
- compliance with Applicable Law;
- regulatory reporting and cooperation;
- maintenance of accounting, audit and Transaction records;
- enforcement or defence of legal rights;
- prevention of misuse of the Services; and
- management of Provider risk.
Where the Provider acts as a Data Controller, it shall be independently responsible for complying with the obligations applicable to it under Applicable Data Protection Law.
3.3 Merchant as Data Controller
The Merchant will ordinarily act as a Data Controller in relation to Personal Data it collects or determines the purposes and means of Processing for in connection with:
- its Customers;
- its Beneficiaries;
- its employees and personnel;
- its Authorised Users; and
- its own business activities.
The Merchant is responsible for complying with Applicable Data Protection Law in respect of those activities.
3.4 Provider as Data Processor
Where the Provider Processes Personal Data solely on behalf of the Merchant and on the Merchant’s documented instructions in connection with the Services, the Provider shall act as a Data Processor in respect of that Processing.
The provisions of these Data Terms relating specifically to Processing on behalf of the Merchant shall apply accordingly.
3.5 No Assumption of Merchant Obligations
Nothing in these Data Terms transfers to the Provider any obligation that Applicable Data Protection Law places directly on the Merchant as a Data Controller.
5MERCHANT INSTRUCTIONS
4.1 Documented Instructions
Where the Provider acts as a Data Processor for the Merchant, the Provider shall Process Personal Data only on documented instructions from the Merchant, unless Applicable Law requires otherwise.
The Merchant’s documented instructions include:
- these Data Terms;
- the TOS;
- Transactions and requests submitted through the Platform;
- configuration of the Merchant Account;
- authorised API instructions;
- support requests; and
- other lawful written instructions agreed by the Provider.
4.2 Scope of Instructions
The Merchant instructs the Provider to Process Personal Data as reasonably necessary to:
- provide the Services;
- route and transmit Transactions;
- communicate with Payment Partners and Payment Networks;
- process or facilitate Payouts and Refunds;
- maintain Transaction records;
- provide reconciliation and reporting;
- provide technical and merchant support;
- manage security and fraud;
- investigate disputes and Chargebacks;
- maintain Platform functionality; and
- perform other Processing reasonably necessary to provide the Services.
4.3 Unlawful Instructions
The Provider is not required to comply with an instruction that it reasonably believes would:
- breach Applicable Law;
- breach a binding regulatory requirement;
- breach a Payment Partner requirement;
- materially compromise Platform or information security; or
- expose another merchant’s Personal Data or Confidential Information.
Where legally permitted and reasonably practicable, the Provider shall inform the Merchant of the relevant concern.
6MERCHANT DATA PROTECTION OBLIGATIONS
5.1 Lawful Collection and Processing
The Merchant represents and warrants that Personal Data disclosed or made available to the Provider has been lawfully collected and may lawfully be Processed for the purposes contemplated by the Services.
5.2 Notices and Lawful Basis
The Merchant is responsible for:
- providing appropriate privacy notices to Data Subjects;
- obtaining consents where consent is required;
- establishing another lawful basis for Processing where appropriate;
- informing Data Subjects of relevant disclosures to the Provider, Payment Partners and other recipients where required;
- complying with restrictions applicable to sensitive Personal Data; and
- complying with other obligations applicable to the Merchant under Applicable Data Protection Law.
5.3 Merchant Instructions
The Merchant shall not instruct the Provider to Process Personal Data:
- unlawfully;
- for purposes unrelated to the Services;
- in breach of a Data Subject’s applicable rights;
- in breach of confidentiality obligations applicable to the Merchant; or
- where the Merchant does not have the authority to provide the relevant instruction.
5.4 Data Minimisation
The Merchant shall not submit Personal Data through the Platform that is unnecessary for the relevant Transaction or Service.
5.5 Sensitive Information
The Merchant shall not provide sensitive Personal Data to the Provider unless:
- such Processing is reasonably necessary for the Services;
- the Provider has requested or expressly permitted the relevant category of information; and
- the Merchant has satisfied all requirements under Applicable Data Protection Law.
5.6 Accuracy
The Merchant is responsible for taking reasonable steps to ensure Personal Data supplied by it to the Provider is accurate, complete and current where required for the relevant Processing purpose.
7PROVIDER PROCESSING OBLIGATIONS
Where the Provider acts as a Data Processor on behalf of the Merchant, the Provider shall:
- Process Personal Data in accordance with the Merchant’s documented instructions and Applicable Data Protection Law;
- ensure persons authorised to Process Personal Data are subject to appropriate confidentiality obligations;
- maintain appropriate technical and organisational security measures;
- provide reasonable assistance in responding to Data Subject requests where required under Clause 12;
- provide reasonable assistance regarding Personal Data Breaches as provided in Clause 9;
- comply with applicable requirements relating to Sub-processors;
- comply with applicable cross-border transfer requirements;
- retain Personal Data only for appropriate periods; and
- make available reasonable information regarding its compliance as provided in Clause 15.
8CONFIDENTIALITY AND PERSONNEL
7.1 Confidentiality
The Provider shall ensure that personnel authorised to Process Personal Data are subject to appropriate obligations of confidentiality.
7.2 Access Limitation
Access to Personal Data shall be limited, where reasonably practicable, to personnel who require access for:
- provision of the Services;
- security;
- support;
- compliance;
- fraud and risk management;
- maintenance of the Platform; or
- another legitimate purpose connected with the Services.
7.3 Personnel Controls
The Provider shall maintain reasonable measures designed to ensure personnel with access to Personal Data understand and comply with applicable confidentiality, privacy and information-security requirements.
9INFORMATION SECURITY
8.1 Security Programme
The Provider shall maintain reasonable administrative, technical and organisational safeguards appropriate to:
- the nature of the Personal Data;
- the sensitivity of the Personal Data;
- the volume of Personal Data;
- the nature of the Processing;
- reasonably foreseeable security risks; and
- the Provider’s role in relation to the relevant Processing.
8.2 Security Objectives
The Provider’s security measures shall be designed to protect Personal Data against:
- unauthorised access;
- unauthorised disclosure;
- unauthorised alteration;
- accidental or unlawful loss;
- accidental or unlawful destruction;
- misuse;
- compromise of credentials; and
- other material security threats.
8.3 Security Measures
Depending on the relevant system, Processing activity and risk, the Provider’s security programme may include measures relating to:
- identity and access management;
- role-based or least-privilege access controls;
- authentication controls;
- credential and secrets management;
- encryption or other appropriate protection of data in transit;
- encryption or other appropriate protection of stored data where appropriate to risk;
- system and application logging;
- security monitoring;
- vulnerability management;
- security patching;
- malware protection;
- secure configuration;
- network and environment security;
- backup and recovery;
- incident response;
- business continuity and disaster recovery;
- segregation appropriate to the Platform architecture;
- vendor and service-provider security;
- personnel confidentiality and security awareness; and
- secure deletion or disposal where applicable.
8.4 Security Is Risk-Based
The Merchant acknowledges that security measures may vary according to the relevant Service, environment, Payment Partner, architecture and risks.
Nothing in these Data Terms constitutes a warranty that a security incident will never occur.
8.5 Merchant Security Responsibilities
The Merchant shall maintain reasonable security measures for Merchant Systems and shall be responsible for:
- securing its Merchant Account;
- protecting usernames and passwords;
- protecting API credentials;
- protecting authentication tokens;
- protecting private keys;
- restricting access to Authorised Users;
- promptly removing access for former personnel;
- implementing appropriate approval controls;
- securing devices and systems used to access the Platform;
- maintaining appropriate security of its websites and applications; and
- promptly notifying the Provider of actual or suspected credential compromise.
8.6 PCI DSS
Where either Party stores, Processes or transmits payment card data, that Party shall comply with the Payment Card Industry Data Security Standard and applicable Payment Network security requirements to the extent applicable to its environment and responsibilities.
10PERSONAL DATA BREACHES AND SECURITY INCIDENTS
9.1 Provider Incident Response
The Provider shall maintain reasonable procedures to identify, investigate, contain and respond to suspected Personal Data Breaches affecting Personal Data Processed in connection with the Services.
9.2 Notification Where Provider Is Processor
Where the Provider acts as a Data Processor and becomes aware of a Personal Data Breach affecting Personal Data Processed on behalf of the Merchant, the Provider shall notify the Merchant without undue delay where such notification is reasonably necessary to enable the Merchant to comply with its obligations under Applicable Data Protection Law.
9.3 Information Provided
To the extent reasonably available and legally permitted, the Provider’s notification may include:
- the nature of the Personal Data Breach;
- the categories of Personal Data affected;
- the categories or approximate number of affected Data Subjects, where known;
- the likely consequences of the Personal Data Breach;
- mitigation or remediation measures taken or proposed;
- relevant dates or time periods; and
- contact information for reasonable follow-up.
Information may be supplied in phases as the investigation progresses.
9.4 No Admission
Notification of a Personal Data Breach does not constitute an admission of fault, liability or breach of these Data Terms.
9.5 Regulatory Notifications
Each Party shall be responsible for determining whether it is required to notify:
- the Personal Data Protection Commissioner;
- affected Data Subjects;
- another regulator;
- a Payment Partner;
- a Payment Network; or
- another person,
in respect of a Personal Data Breach for which that Party is the relevant Data Controller or otherwise bears the applicable notification obligation.
9.6 Cooperation
The Parties shall reasonably cooperate where information held by one Party is required for the other Party to comply with legally applicable Personal Data Breach obligations.
9.7 Merchant Security Incidents
The Merchant shall notify the Provider without undue delay if it becomes aware of a security incident that may materially affect:
- the Platform;
- the Merchant Account;
- API credentials;
- Transactions;
- Personal Data Processed through the Services; or
- Payment Partner systems accessed through the Services.
11SUB-PROCESSORS, PAYMENT PARTNERS AND SERVICE PROVIDERS
10.1 General Authorisation
The Merchant authorises the Provider to engage Payment Partners, cloud infrastructure providers, data-centre providers, fraud-prevention providers, security providers, communications providers, customer-support providers and other service providers reasonably necessary to provide and operate the Services.
10.2 Sub-processor Obligations
Where the Provider appoints a Sub-processor to Process Personal Data on behalf of the Merchant, the Provider shall impose appropriate contractual data-protection and security obligations to the extent required by Applicable Data Protection Law.
10.3 Provider Responsibility
Where required by Applicable Data Protection Law, the Provider shall remain responsible for obligations expressly applicable to it regarding Processing performed by its Sub-processors.
10.4 Payment Partners
The Merchant acknowledges that certain Payment Partners may Process Personal Data as independent Data Controllers for their own:
- regulatory requirements;
- payment processing activities;
- fraud-prevention activities;
- financial-crime controls;
- Transaction execution;
- settlement; and
- legal obligations.
Such Processing may be subject to the Payment Partner’s own terms and privacy practices.
10.5 Changes to Providers
The Provider may add, replace or remove service providers and Payment Partners in the ordinary course of operating the Services.
Where Applicable Data Protection Law requires notice, consent, authorisation or another procedure in connection with a new Sub-processor, the Provider shall comply with the applicable requirement.
12CROSS-BORDER PROCESSING AND TRANSFERS
11.1 International Processing
The Merchant acknowledges that Personal Data may be Processed, transmitted, accessed or stored outside Malaysia where reasonably necessary for:
- Payment Partner connectivity;
- cloud infrastructure;
- fraud and security services;
- technical support;
- Transaction routing;
- service resilience; or
- other legitimate purposes connected with the Services.
11.2 Applicable Requirements
A Party transferring Personal Data outside Malaysia shall take such steps and implement such safeguards as are required by Applicable Data Protection Law.
11.3 Merchant Authorisation
To the extent required for the Provider to perform the Services and permitted by Applicable Data Protection Law, the Merchant authorises the Provider to facilitate cross-border Processing in accordance with these Data Terms.
11.4 Merchant Transfers
The Merchant remains responsible for ensuring that any instruction it gives requiring an international transfer of Personal Data is lawful.
13DATA SUBJECT RIGHTS
12.1 Responsibility
Each Party is responsible for responding to Data Subject requests to the extent required by Applicable Data Protection Law having regard to its role in relation to the relevant Personal Data.
12.2 Requests Received by Provider as Processor
Where the Provider:
- acts as a Data Processor in respect of the relevant Personal Data; and
- receives a request from a Data Subject that primarily concerns Processing controlled by the Merchant,
the Provider may refer the Data Subject to the Merchant where legally permitted.
12.3 Assistance
Taking into account the nature of the Processing and information reasonably available to the Provider, the Provider shall provide reasonable assistance to the Merchant where necessary for the Merchant to respond to applicable requests concerning:
- access;
- correction;
- withdrawal of consent;
- restriction or prevention of certain Processing;
- direct marketing objections;
- data portability where applicable; or
- other rights under Applicable Data Protection Law.
12.4 Costs
Where a request requires material bespoke technical work beyond functionality ordinarily provided through the Platform, the Provider may charge reasonable costs for such assistance where permitted by Applicable Law and agreed with the Merchant in advance.
14DATA PROTECTION IMPACT ASSESSMENTS AND REGULATORY COOPERATION
13.1 Impact Assessments
Where the Merchant is required by Applicable Data Protection Law to carry out a data protection impact assessment concerning the Provider’s Processing on behalf of the Merchant, the Provider shall provide reasonable information and assistance relating to the Provider’s Processing activities, taking into account:
- the nature of the Processing;
- information available to the Provider;
- confidentiality;
- security restrictions; and
- the rights of other merchants and third parties.
13.2 Regulatory Consultation
Where Applicable Data Protection Law requires consultation with a competent authority concerning Processing carried out through the Services, the Parties shall reasonably cooperate to the extent relevant to their respective responsibilities.
13.3 Regulatory Requests
Each Party shall cooperate reasonably with lawful requests or investigations by competent data-protection authorities relating to Processing for which that Party has responsibility.
Nothing requires a Party to disclose legally privileged, security-sensitive or unrelated confidential information except where required by Applicable Law.
15DATA PROTECTION OFFICERS AND PRIVACY CONTACTS
14.1 Appointment
Each Party shall appoint a Data Protection Officer where required by Applicable Data Protection Law.
14.2 Contact Details
Where a Party is required to appoint a Data Protection Officer, it shall maintain appropriate contact information for that officer in accordance with Applicable Data Protection Law.
14.3 Cooperation
The Data Protection Officers or other designated privacy contacts of the Parties may communicate directly where reasonably necessary concerning:
- regulatory compliance;
- Personal Data Breaches;
- Data Subject requests;
- regulatory enquiries;
- impact assessments; or
- other material data-protection issues.
16RETENTION, RETURN AND DELETION
15.1 Retention
Personal Data may be retained for the period reasonably necessary for:
- provision of the Services;
- Transaction processing;
- reconciliation;
- accounting;
- audit;
- compliance with Applicable Law;
- regulatory obligations;
- fraud prevention and investigation;
- security;
- dispute resolution;
- Chargebacks and Refunds;
- establishment, exercise or defence of legal claims; and
- other lawful retention purposes.
15.2 Processor Data Following Termination
Following termination of the Services, Personal Data Processed solely by the Provider as a Data Processor on behalf of the Merchant shall be deleted, anonymised, returned or otherwise handled in accordance with:
- the applicable retention period;
- Applicable Law;
- reasonable technical processes; and
- the Provider’s legitimate legal and compliance obligations.
15.3 Legally Required Retention
The Provider may retain Personal Data after termination where retention is reasonably necessary or required for:
- Applicable Law;
- regulatory obligations;
- fraud prevention;
- accounting and audit;
- payment disputes;
- Chargebacks;
- security;
- legal claims; or
- enforcement of contractual rights.
Personal Data retained for such purposes shall remain subject to applicable confidentiality and security obligations.
15.4 Backups
Personal Data contained in backups may remain until overwritten or deleted in accordance with the Provider’s normal backup and retention cycle, provided such Personal Data remains appropriately protected and is not restored for ordinary business use except where necessary for recovery, legal or security purposes.
17AUDIT AND COMPLIANCE INFORMATION
16.1 Information
Upon reasonable written request, the Provider shall make available information reasonably necessary to demonstrate compliance with its applicable Data Processor obligations under these Data Terms.
Such information may include, where appropriate and available:
- descriptions of relevant security controls;
- compliance summaries;
- policies or policy summaries;
- third-party assurance information; or
- responses to reasonable security questionnaires.
16.2 Additional Audit
Where additional audit rights are required by Applicable Data Protection Law and the information provided under Clause 16.1 is insufficient, the Parties shall reasonably cooperate regarding an appropriate audit arrangement.
16.3 Audit Restrictions
Any audit or review shall:
- be limited to Processing relevant to the Merchant;
- be proportionate to the relevant risk;
- avoid unreasonable disruption to the Provider;
- comply with reasonable Provider security procedures;
- protect Confidential Information;
- not provide access to Personal Data belonging to other merchants;
- not provide access to Payment Partners’ confidential systems;
- not require disclosure of information that would materially compromise the security of the Platform; and
- not require disclosure of information protected by legal privilege, except where Applicable Law requires otherwise.
16.4 Costs
Unless an audit identifies a material breach by the Provider of these Data Terms, each Party shall bear its own costs and the Merchant shall bear any reasonable external costs specifically incurred by the Provider in facilitating a Merchant-requested bespoke audit.
18DATA INTEGRITY AND QUALITY
Each Party shall take reasonable steps, having regard to the purpose for which Personal Data is Processed, to ensure that Personal Data under its control is sufficiently accurate, complete and current for that purpose where required by Applicable Data Protection Law.
The Provider may rely on Personal Data supplied by the Merchant, Customer, Beneficiary, Payment Partner or other authorised source unless the Provider knows or reasonably should know that the relevant information is materially incorrect.
19PRIVACY BY DESIGN AND SERVICE DEVELOPMENT
The Provider may take reasonable data-protection and security considerations into account when:
- designing new Platform functionality;
- materially modifying Processing activities;
- implementing new Payment Partners;
- selecting relevant service providers;
- developing security controls; and
- introducing new forms of Personal Data Processing.
Where appropriate to the nature and risk of the Processing, this may include consideration of:
- data minimisation;
- access limitation;
- appropriate retention;
- security;
- segregation;
- transparency; and
- protection of Data Subject rights.
20AGGREGATED AND ANONYMISED DATA
Nothing in these Data Terms prevents the Provider from generating or using information that has been aggregated or anonymised so that it no longer constitutes Personal Data under Applicable Data Protection Law.
Such information may be used for:
- analytics;
- security;
- fraud analysis;
- service improvement;
- capacity planning;
- statistical purposes; and
- development and operation of the Platform,
provided that the Provider does not use such information to re-identify a Data Subject contrary to Applicable Data Protection Law.
21LEGAL DISCLOSURES
The Provider may disclose Personal Data where reasonably necessary to:
- comply with Applicable Law;
- comply with a court order;
- comply with a lawful regulatory or governmental request;
- comply with Payment Partner or Payment Network obligations applicable to the relevant Transaction;
- investigate fraud or unlawful activity;
- protect the security or integrity of the Platform;
- establish, exercise or defend legal rights; or
- protect the rights, property or safety of the Provider, Merchant, Customers or other persons,
subject to Applicable Data Protection Law.
Where legally prohibited from informing the Merchant of such disclosure, the Provider shall not be required to do so.
22RECORDS
Each Party shall maintain such records concerning its Processing activities as are required by Applicable Data Protection Law.
The Provider may maintain electronic records concerning:
- Merchant onboarding;
- verification;
- Transaction Processing;
- access and authentication;
- security events;
- disclosures;
- support;
- compliance activities;
- consent or acceptance records where relevant; and
- other activities reasonably necessary for legal, security and operational purposes.
23CHANGES TO THESE DATA TERMS
22.1 Changes
The Provider may amend these Data Terms where reasonably necessary to reflect:
- changes in Applicable Data Protection Law;
- regulatory guidance or requirements;
- changes in the Services;
- changes in Processing activities;
- security developments;
- changes in Payment Partners or service providers; or
- other legitimate operational requirements.
22.2 Material Changes
Where an amendment materially affects the rights or obligations of the Merchant concerning Personal Data, the Provider shall provide such prior notice as is reasonably practicable or required by Applicable Law.
22.3 Effective Date of Changes
An updated version shall take effect on the date specified in the relevant notice or updated Data Terms.
Where Applicable Law requires new consent or acceptance for a particular change, the Provider shall obtain such consent or acceptance before relying on the change to the extent required by law.
24LIABILITY
The allocation, exclusions and limitations of liability applicable to these Data Terms shall be governed by the liability provisions of the TOS unless Applicable Law requires otherwise.
Nothing in these Data Terms excludes or limits liability to the extent that such liability cannot lawfully be excluded or limited.
25TERM AND TERMINATION
24.1 Term
These Data Terms commence when they first become applicable to the Merchant and continue for so long as the Provider Processes Personal Data in connection with the Services.
24.2 Termination
These Data Terms terminate when:
- the TOS terminate; and
- the Provider has ceased Processing Personal Data for purposes requiring these Data Terms,
subject to applicable retention obligations.
24.3 Survival
Provisions concerning:
- confidentiality;
- security;
- retention;
- deletion;
- audits;
- liability;
- regulatory cooperation; and
- provisions intended by their nature to survive,
shall continue for so long as relevant Personal Data remains Processed or retained.
26GENERAL
25.1 Electronic Acceptance
These Data Terms may be accepted electronically together with the TOS or through another electronic acceptance mechanism made available by the Provider.
25.2 No Third-Party Rights
Except where Applicable Law expressly provides otherwise, a person who is not a Party has no right to enforce these Data Terms.
25.3 Severability
If any provision is invalid or unenforceable, it shall be modified to the minimum extent necessary to make it valid and enforceable or, where modification is not possible, severed without affecting the remaining provisions.
25.4 Governing Law
These Data Terms are governed by the laws of Malaysia.
The dispute and jurisdiction provisions of the TOS apply to these Data Terms.
27SCHEDULE A: PROCESSING PARTICULARS
1. Subject Matter
Processing of Personal Data in connection with the provision, operation, security and administration of the Services.
2. Duration
Processing may occur throughout the term of the Merchant relationship and thereafter for applicable retention periods.
3. Categories of Data Subjects
Personal Data may relate to:
- Customers;
- Beneficiaries;
- Merchant directors;
- Merchant shareholders;
- beneficial owners;
- Merchant employees and personnel;
- Authorised Users;
- authorised representatives;
- Merchant business contacts; and
- other individuals whose Personal Data is lawfully Processed in connection with the Services.
4. Categories of Personal Data
Depending on the Services used, Personal Data may include:
Identification information
- name;
- identification information;
- date of birth where required;
- nationality where required;
- identity-verification information; and
- other identification information required for compliance.
Contact information
- email address;
- telephone number;
- postal or business address; and
- other relevant contact details.
Business and relationship information
- job title;
- employer;
- directorship;
- shareholding;
- beneficial ownership;
- authority to act; and
- Merchant relationship information.
Transaction and payment-related information
- Transaction identifiers;
- Transaction amount;
- currency;
- payment method;
- timestamps;
- Transaction status;
- settlement information;
- Refund information;
- Chargeback information;
- Payout information;
- Beneficiary information; and
- payment-related identifiers.
Account and technical information
- Merchant Account identifiers;
- Authorised User identifiers;
- device information;
- IP addresses;
- log information;
- authentication information;
- API activity;
- technical identifiers; and
- security records.
Support and communication information
- support tickets;
- correspondence;
- complaints;
- dispute records; and
- other communications relating to the Services.
Fraud, compliance and risk information
- fraud indicators;
- risk scores or signals;
- sanctions screening results;
- due-diligence information;
- security indicators;
- investigation records; and
- other information reasonably required for risk or compliance purposes.
5. Nature of Processing
Processing may include:
- collection;
- recording;
- organisation;
- storage;
- retrieval;
- consultation;
- transmission;
- routing;
- matching;
- reconciliation;
- fraud and security analysis;
- disclosure to authorised Payment Partners and service providers;
- restriction;
- correction;
- deletion;
- destruction; and
- anonymisation.
6. Purposes
Personal Data may be Processed for:
- Merchant registration;
- Merchant onboarding;
- identity and business verification;
- provision of the Services;
- Transaction routing and processing;
- settlement administration;
- Payouts;
- Refunds;
- reconciliation;
- reporting;
- Merchant support;
- fraud prevention;
- risk management;
- information security;
- compliance;
- sanctions and financial-crime screening;
- dispute and Chargeback handling;
- audit;
- service administration;
- legal and regulatory obligations; and
- maintenance of records.
7. Processing Frequency
Processing may occur continuously, periodically or on an event-driven basis depending on Merchant use of the Services and the relevant Processing activity.
8. Retention
Personal Data may be retained for the period reasonably necessary for:
- the Services;
- legal and regulatory requirements;
- financial and accounting obligations;
- fraud prevention;
- audit;
- security;
- dispute resolution;
- Chargebacks and Refunds; and
- establishment, exercise or defence of legal claims,
after which Personal Data shall be deleted, anonymised or otherwise handled in accordance with Applicable Data Protection Law and applicable retention procedures.
28SCHEDULE B: TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
The Provider shall maintain security measures appropriate to its systems, responsibilities and risk profile.
Such measures may include, as relevant:
1. Access Control
- individual user accounts;
- role-based access;
- least-privilege principles;
- access approval procedures;
- periodic access review; and
- prompt removal of unnecessary access.
2. Authentication and Credentials
- password controls;
- authentication controls appropriate to risk;
- privileged-access controls;
- API credential protection;
- secret and key management; and
- procedures for credential compromise.
3. Communications and Data Protection
- appropriate protection of information transmitted over networks;
- encryption in transit where appropriate;
- encryption or equivalent protection of stored information where appropriate to risk;
- secure handling of sensitive credentials; and
- appropriate segregation of environments and data.
4. Logging and Monitoring
- security logging;
- access logging where appropriate;
- monitoring of relevant system activity;
- security-event detection; and
- retention of logs appropriate to security and compliance needs.
5. Vulnerability and System Management
- vulnerability identification;
- security patching;
- system hardening;
- secure configuration;
- malware protection where appropriate; and
- remediation of material security vulnerabilities.
6. Application and Platform Security
- security considerations in software development;
- access restrictions;
- appropriate testing;
- change management;
- vulnerability remediation; and
- protection of production environments.
7. Incident Management
- security incident procedures;
- investigation;
- containment;
- remediation;
- escalation;
- breach assessment; and
- post-incident review where appropriate.
8. Resilience
- backups;
- recovery arrangements;
- business continuity measures;
- disaster recovery planning; and
- measures designed to maintain or restore availability appropriate to the Services.
9. Personnel Security
- confidentiality obligations;
- access restrictions;
- appropriate security awareness;
- procedures relating to personnel changes; and
- disciplinary or governance measures appropriate to the organisation.
10. Third-Party Risk
- appropriate assessment of material service providers;
- contractual security obligations where appropriate;
- confidentiality obligations;
- restriction of access to what is reasonably required; and
- oversight proportionate to the nature and risk of the service.
11. Data Lifecycle
- data minimisation where appropriate;
- retention controls;
- secure deletion or disposal;
- restriction of unnecessary copies; and
- protection of backups.