At SSN Paytech, we treat the processing of personal data as a responsibility grounded in trust, accountability, and legal compliance. This Data Processing Agreement (DPA) defines the relationship between you, acting as the Data Controller, and us, acting as the Data Processor, and explains how Personal Data is handled while delivering our services.
Throughout this agreement, we, our, or us refer to SSN Paytech, while you and your refer to the entity accepting this DPA and using our services. This document establishes a shared understanding of how Personal Data is collected, processed, stored, and protected in accordance with applicable laws and regulatory standards.
Clear role definitions ensure responsible and compliant data handling.
The Data Controller determines why and how Personal Data is processed. This includes deciding the lawful basis for processing and ensuring compliance with all applicable data protection regulations.
The Data Processor processes Personal Data only on documented instructions from the Data Controller and solely to provide the agreed services. The Processor does not use Personal Data for independent purposes.
Defining these roles creates accountability, transparency, and a structured approach to data protection.
Personal Data is processed only for legitimate, defined purposes that support secure and efficient service delivery.
Processing activities may include enabling payment transactions, conducting KYC verification, identifying and preventing fraudulent activity, supporting optional security features such as two-factor authentication, and maintaining records required for reconciliation and reporting.
All processing activities follow RBI, and applicable payment network regulations to ensure lawful, secure, and consistent data handling.
Safeguarding Personal Data is a core operational priority at SSN Paytech. We implement layered security practices aligned with recognized industry standards. These include encrypting data during transmission and storage, enforcing multi-step authentication, securely managing cryptographic keys, and conducting regular vulnerability assessments and penetration testing.
Our teams receive ongoing training on confidentiality and data protection obligations, ensuring that security practices remain effective and up to date.
Respecting individual rights is central to responsible data processing. In coordination with the Data Controller, we support requests from data subjects to access their personal data, correct inaccuracies, request deletion where legally allowed, obtain data in a portable format, or restrict or object to certain processing activities.
This cooperative approach ensures that data subject rights are fulfilled accurately and within required timelines.
In certain cases, trusted third-party service providers may be engaged as Subprocessors to assist with specific processing activities.
Subprocessors are appointed only with the prior written consent of the Data Controller. Each Subprocessor is required to follow equivalent data protection and security standards and to enter into binding agreements governing Personal Data handling.
These controls ensure accountability and continuity of protection, even when processing is delegated.
Despite robust safeguards, data incidents may occur. If a Personal Data breach is identified, SSN Paytech notifies the Data Controller within 24 hours. The notification includes details of the incident, the categories and estimated volume of affected data, actions taken to contain the issue, and measures planned to prevent recurrence. Timely notification enables the Controller to take appropriate regulatory and operational steps.
Transparency supports long-term trust. The Data Controller may conduct audits of the Data Processor, subject to reasonable notice, to verify compliance with this DPA. During such audits, the Processor provides relevant documentation, internal policies, certifications, and evidence demonstrating adherence to agreed obligations. Audits help confirm that data protection commitments are actively maintained.
Personal Data is retained only for as long as required to fulfill service obligations or meet legal and regulatory requirements. Once data is no longer necessary, it is securely deleted or returned to the Data Controller. Extended retention occurs only where mandated by applicable laws or regulations. This approach ensures controlled data lifecycle management and minimizes unnecessary storage.
Data protection and payment regulations evolve over time. If changes in law affect how Personal Data must be processed, SSN Paytech promptly informs the Data Controller. This allows both parties to adjust procedures and maintain continuous compliance without disrupting services.
Each party is accountable for fulfilling its obligations under this DPA. If a party fails to comply with its responsibilities, that party bears liability for resulting damages. The Data Processor agrees to indemnify the Data Controller against claims, fines, or losses arising from the Processor’s failure to meet data protection requirements. This ensures fair allocation of responsibility and risk.
This DPA is governed by the laws of India. Any disputes arising in connection with this agreement are subject to the exclusive jurisdiction of the courts of India, providing a consistent legal framework for resolution.
Any modification to this DPA must be made in writing and agreed upon by both parties. This ensures that changes are clearly documented and that responsibilities remain transparent and mutually understood.
By accepting this DPA, both parties confirm that they have reviewed, understood, and agreed to its terms. This acknowledgment reflects a shared commitment to lawful, secure, and responsible handling of Personal Data, reinforcing trust between the Data Controller and the Data Processor.