Data Processing Addendum — Astrada

Legal

Our policies and agreements governing the use of Astrada's services.

Privacy Policy Cookies Policy Data Processing Addendum

Last updated: 21 May 2026

Background

In accordance with clause 10 of the Agreement, this Data Processing Addendum ("DPA") sets out the basis on which Astrada uses the Customer Personal Data (as defined below) for the purposes of providing the Astrada Service.

For the purposes of this DPA and the Data Protection Laws, the Customer is the controller and Astrada is the processor of Customer Personal Data.

In the event of a conflict between any of the provisions of this DPA and the remaining provisions of the Agreement, the provisions of this DPA shall prevail.

Both parties will comply with all applicable requirements of the Data Protection Laws (as defined below). This DPA is in addition to, and does not relieve, remove or replace, a party's obligations under the Data Protection Laws.

Definitions

Unless otherwise set out below, each capitalized term in this DPA shall have the meaning set out in clause 2 of the Agreement, and the following capitalized terms used in this DPA shall be defined as follows:

Data Processing

Instructions for Data Processing

Required Consents and Disclosures

Where required by applicable Data Protection Laws, the Customer will ensure that it has obtained or will obtain all necessary consents, and has provided appropriate disclosures and notices, for the processing of Customer Personal Data by Astrada and the Card Networks in accordance with the Agreement (including the Permitted Use), including consent from Users to enable the Card Networks to collect, process and share Customer Personal Data relating to the Users for the purposes set out in the Agreement (including this DPA).

Transfer of Personal Data

Authorized Sub-processors

Liability of Sub-processors

Astrada shall at all times remain responsible for compliance with its obligations under the DPA and will be liable to the Customer for the acts and omissions of any Sub-processor appointed by Astrada as if they were the acts and omissions of Astrada.

International Transfers

Data Security, Audits and Security Notifications

Astrada Security Obligations

Astrada shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including the measures set out in Annex 1.

Security Audits

Astrada shall make available to the Customer, and the Customer may audit (using independent third party auditors at Customer's cost, upon at least 30 days' notice, and at reasonable intervals but no more than once annually unless there are reasonable grounds for additional audits, including suspected breaches or regulatory requirements), all information reasonably necessary to demonstrate compliance with this DPA (including the technical and organizational measures as set out in Annex 1). The Customer's right to audit in this paragraph 5.2 is subject always to the confidentiality provisions of the Agreement. Customer acknowledges and agrees that Astrada may, at its discretion, provide a current audit report (such as PCI-DSS compliance audit) in lieu of granting audit access provided that such audit report adequately addresses the scope of processing under this DPA including Article 28 GDPR. Where such a report does not reasonably demonstrate compliance, Astrada shall provide additional information reasonably requested by the Customer and, if necessary, permit the Customer to exercise its audit rights in accordance with this Section 5.2.

Data Protection Impact Assessments

Astrada shall provide reasonable assistance to the Customer (at Customer's cost) with the Customer's obligations to conduct Data Protection Impact Assessments under applicable Data Protection Laws, taking into account the nature of processing and information available to Astrada.

Security Incident Notification

If Astrada or any Sub-processor becomes aware of a Security Incident, Astrada will (a) notify the Customer of the Security Incident within seventy-two (72) hours, (b) investigate the Security Incident and provide such reasonable assistance to the Customer (and any law enforcement or regulatory official) as required to investigate the Security Incident, and (c) take steps to remedy any non-compliance with this DPA.

Astrada Employees and Personnel

Astrada shall treat the Customer Personal Data as the Confidential Information of the Customer, and shall ensure that:

Individuals' Rights

Requests from Individuals

Government Disclosure

Astrada shall notify the Customer of any request for the disclosure of Customer Personal Data by a governmental or regulatory body or law enforcement authority (including any data protection supervisory authority), unless otherwise prohibited by law or a legally binding order of such body or agency.

Deletion of Data

Subject to paragraph 7.2 below, the Customer may in its absolute discretion notify Astrada in writing within thirty (30) days of the date of expiry or termination of the Agreement to require Astrada to delete and procure the deletion of all copies of Customer Personal Data processed by Astrada and Astrada shall, within 60 days:

Astrada and its Sub-processors may retain Customer Personal Data to the extent required by applicable laws and only to the extent and for such period as required by applicable laws and always provided that Astrada shall ensure the confidentiality of all such Customer Personal Data and shall ensure that such Customer Personal Data is only processed as necessary for the purpose(s) specified in the applicable laws requiring its storage and for no other purpose. In such cases, Astrada and its Sub-processors will be considered controllers of that data, as it will only be processed to comply with legal obligations.

Annex 1 — Security Measures

Pursuant to Article 32 of Regulation (EU) 2016/679 ("GDPR"), Astrada has implemented and maintains appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to the rights and freedoms of natural persons.

Information Security Governance and Program Oversight

Astrada maintains a formal, documented information security program approved by management and supported by written policies, standards, and procedures. The program is designed to:

Astrada contractually requires its Sub-processors to implement technical and organizational measures that provide a level of protection no less protective than those described in this Annex.

Risk Assessment and Continuous Improvement

Access Control and Identity Management

Astrada implements administrative, technical, and logical access controls to ensure that access to Customer Personal Data and related systems is limited to authorized personnel with a legitimate business need, including:

Personnel Security and Training

Data Retention and Secure Deletion

Security Incident and Breach Management

Astrada maintains documented security incident response and breach management procedures designed to:

Monitoring, Logging, and Vulnerability Management

Security Testing, Audits, and Certifications

Astrada regularly evaluates the effectiveness of its information security controls, including through:

Findings from testing and audits are reviewed and remediation activities are tracked to completion where appropriate.

Endpoint and Device Security

Astrada implements security controls for endpoint devices used to access Customer Personal Data, including:

Sub-processor Security Management

Astrada conducts due diligence on Sub-processors prior to engagement and contractually requires them to implement appropriate technical and organizational security measures. Astrada periodically reviews Sub-processor security assurances as part of its vendor management process.

Review and Updates

Astrada reviews and updates these Technical and Organizational Security Measures periodically and in response to material changes in applicable laws, processing activities, or the threat landscape.

Annex 2 — Details of Processing

Subject Matter and Duration of Processing

Nature and Purpose of Processing

Location of Processing

Categories of Data Subjects

Users of the Customer platform who attempt to enroll Payment Cards.

Types of Personal Data