NexliPay
← Back to nexlipay.com

Data Protection

Controller and processor responsibilities, our sub-processor list, transfer safeguards and how we help you meet your own GDPR duties.

Last updated: [[DATE]]

Draft — not yet legal advice

This document is a working draft written to give a qualified lawyer a strong starting point. Every highlighted value is a fact only NexliPay can supply — entity name, jurisdiction, registration and licence numbers, addresses, named contacts. Do not publish this page until a solicitor licensed in your operating jurisdiction has reviewed it and every placeholder is filled with a true value.

01Controller and processor roles

Our role depends on the data. For your own account, billing and verification records, NexliPay is the controller. For transaction data we route on your behalf, you are the controller and NexliPay is your processor, acting only on your documented instructions.

DataNexliPay acts asYou act as
Merchant account and billing recordsControllerData subject / representative
KYC, KYB and AML recordsController (legal obligation)Data subject / representative
Transaction and cardholder metadataProcessorController
Routing configuration and logsProcessorController
Website analyticsController

02Data processing agreement

Our DPA is incorporated into the Terms of Service and covers Article 28 UK/EU GDPR requirements: subject matter and duration, nature and purpose, categories of data and data subjects, confidentiality obligations, security measures, sub-processing, assistance with data subject rights, breach notification, deletion or return on termination, and audit rights.

A signable standalone copy is available at DPA DOWNLOAD LINK or on request from privacy@nexlipay.com.

03Sub-processors

We use the sub-processors below. We give SUB-PROCESSOR NOTICE PERIOD notice of additions, and you may object on reasonable data protection grounds.

Sub-processorPurposeLocation
HOSTING PROVIDERInfrastructure hostingREGION
DATABASE PROVIDERManaged databaseREGION
SCREENING PROVIDERKYC, KYB and sanctions screeningREGION
EMAIL PROVIDERTransactional emailREGION
SUPPORT PROVIDERCustomer support toolingREGION
ANALYTICS PROVIDERProduct analyticsREGION

04International transfers

Personal data is stored primarily in PRIMARY DATA REGION. Where data is transferred outside the UK or EEA we rely on adequacy where available, and otherwise on the UK IDTA or EU Standard Contractual Clauses supported by a transfer risk assessment. Current destinations: TRANSFER DESTINATIONS.

05Data minimisation

  • We hold no full card numbers or CVV values — only tokens and metadata such as BIN, last four digits and network.
  • Verification documents are held only as long as AML rules require, then deleted on a scheduled job rather than on request.
  • Support tooling and analytics receive pseudonymised identifiers rather than merchant contact details wherever the workflow allows.

06Assisting with data subject requests

Where you receive a request from a cardholder or other data subject relating to data we process for you, contact privacy@nexlipay.com and we will assist within DSR ASSISTANCE SLA. Where we receive such a request directly, we forward it to you rather than responding on your behalf.

07Deletion and return

On termination we return or delete data processed on your behalf within DELETION PERIOD, except where retention is required by law. Records held under AML obligations are retained for 5 years from the end of the relationship and are outside the scope of a deletion request.

08Audit

You may audit our compliance with the DPA once per year, on AUDIT NOTICE PERIOD notice, or more often where a regulator requires it. In most cases our CERTIFICATIONS report will satisfy an audit request without an on-site visit.

Questions?

Write to legal@nexlipay.com or use the contact page.