Data Protection
Controller and processor responsibilities, our sub-processor list, transfer safeguards and how we help you meet your own GDPR duties.
Last updated: [[DATE]]
Draft — not yet legal advice
This document is a working draft written to give a qualified lawyer a strong starting point. Every highlighted value is a fact only NexliPay can supply — entity name, jurisdiction, registration and licence numbers, addresses, named contacts. Do not publish this page until a solicitor licensed in your operating jurisdiction has reviewed it and every placeholder is filled with a true value.
01Controller and processor roles
Our role depends on the data. For your own account, billing and verification records, NexliPay is the controller. For transaction data we route on your behalf, you are the controller and NexliPay is your processor, acting only on your documented instructions.
| Data | NexliPay acts as | You act as |
|---|---|---|
| Merchant account and billing records | Controller | Data subject / representative |
| KYC, KYB and AML records | Controller (legal obligation) | Data subject / representative |
| Transaction and cardholder metadata | Processor | Controller |
| Routing configuration and logs | Processor | Controller |
| Website analytics | Controller | — |
02Data processing agreement
Our DPA is incorporated into the Terms of Service and covers Article 28 UK/EU GDPR requirements: subject matter and duration, nature and purpose, categories of data and data subjects, confidentiality obligations, security measures, sub-processing, assistance with data subject rights, breach notification, deletion or return on termination, and audit rights.
A signable standalone copy is available at DPA DOWNLOAD LINK or on request from privacy@nexlipay.com.
03Sub-processors
We use the sub-processors below. We give SUB-PROCESSOR NOTICE PERIOD notice of additions, and you may object on reasonable data protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| HOSTING PROVIDER | Infrastructure hosting | REGION |
| DATABASE PROVIDER | Managed database | REGION |
| SCREENING PROVIDER | KYC, KYB and sanctions screening | REGION |
| EMAIL PROVIDER | Transactional email | REGION |
| SUPPORT PROVIDER | Customer support tooling | REGION |
| ANALYTICS PROVIDER | Product analytics | REGION |
04International transfers
Personal data is stored primarily in PRIMARY DATA REGION. Where data is transferred outside the UK or EEA we rely on adequacy where available, and otherwise on the UK IDTA or EU Standard Contractual Clauses supported by a transfer risk assessment. Current destinations: TRANSFER DESTINATIONS.
05Data minimisation
- We hold no full card numbers or CVV values — only tokens and metadata such as BIN, last four digits and network.
- Verification documents are held only as long as AML rules require, then deleted on a scheduled job rather than on request.
- Support tooling and analytics receive pseudonymised identifiers rather than merchant contact details wherever the workflow allows.
06Assisting with data subject requests
Where you receive a request from a cardholder or other data subject relating to data we process for you, contact privacy@nexlipay.com and we will assist within DSR ASSISTANCE SLA. Where we receive such a request directly, we forward it to you rather than responding on your behalf.
07Deletion and return
On termination we return or delete data processed on your behalf within DELETION PERIOD, except where retention is required by law. Records held under AML obligations are retained for 5 years from the end of the relationship and are outside the scope of a deletion request.
08Audit
You may audit our compliance with the DPA once per year, on AUDIT NOTICE PERIOD notice, or more often where a regulator requires it. In most cases our CERTIFICATIONS report will satisfy an audit request without an on-site visit.
Questions?
Write to legal@nexlipay.com or use the contact page.