Last updated: October 1st, 2025
This Data Processing Addendum (“DPA”) supplements the Payaz Terms and Conditions (the “Terms”) between S&G Creative Solutions Ltd (“Payaz”) and the entity or individual agreeing to these terms (“Fundraiser”, “you”, or “your”).
This DPA applies where Payaz processes personal data on behalf of the Fundraiser in connection with the provision of the Payaz platform and related services (the “Services”).
For the purposes of applicable data protection law (including the UK General Data Protection Regulation (“UK GDPR”)), the Fundraiser acts as the data controller of any personal data it collects from donors and supporters (“Donation Data”), and Payaz acts as a data processor.
The Fundraiser’s configuration of the Payaz platform and its use of the Services constitute the documented instructions to Payaz regarding processing of Donation Data (“Documented Instructions”). Payaz will only process Donation Data in accordance with these instructions and the Terms.
Each party must comply with all applicable Data Protection Laws in connection with its performance under this DPA.
Payaz will not access, use, or disclose Donation Data except as necessary to provide the Services or as required by law. All Payaz personnel (including contractors) with access to Donation Data are subject to confidentiality obligations.
The Fundraiser authorises Payaz to engage sub-processors for the provision of the Services. Payaz currently uses the following sub-processors:
Payaz will ensure sub-processors only access Donation Data as necessary, enter into written agreements imposing equivalent data protection obligations, and remain liable for sub-processor compliance with this DPA.
4.1 Future Sub-Processors
The Fundraiser acknowledges and accepts that Payaz may change, add, or replace sub-processors at any time without prior notice, provided that:
4.3 Sub-Processor Obligations
Payaz will restrict sub-processors’ access to Donation Data only as necessary to provide the Services, ensure written data protection obligations are in place, and remain responsible for compliance with this DPA and the acts or omissions of its sub-processors.
Payaz may occasionally review or process aggregated or anonymised information relating to how Fundraisers and donors use the platform. Aggregated simply means that any personal details (like names or contact information) have been removed, and the data is grouped together so no individual person or organisation can be identified.
This type of data helps Payaz understand general trends — for example, which features are most used, or how donation patterns change over time — so that we can continue improving the platform and maintaining security and reliability.
Any such analysis will only ever be carried out in a way that protects the privacy of all individuals and Fundraisers, and in line with good industry practice and applicable data protection laws.
Payaz provides the Fundraiser with tools within the Payaz platform to manage donor data and respond to data subject requests. If a data subject contacts Payaz directly, Payaz will forward the request to the Fundraiser.
Payaz implements appropriate technical and organisational measures to protect personal data, including encryption at rest and in transit, secure authentication mechanisms, access controls, and regular internal security reviews.
Payaz will notify the Fundraiser without undue delay, and no later than 72 hours, after becoming aware of a security incident involving Donation Data. Payaz will take reasonable steps to mitigate its effects and cooperate with the Fundraiser in compliance with applicable law.
Within 90 days after termination of the Terms, Payaz will delete Donation Data and all existing copies, unless required by law to retain it. Fundraisers will have 10 days’ access to export their data before deletion.
Upon reasonable written request, Payaz will provide the Fundraiser with information necessary to demonstrate compliance with this DPA. If that information is insufficient, Payaz will allow for an independent audit once every 12 months, under confidentiality obligations and with reasonable notice.
Taking into account the nature of the processing and the information available, Payaz will assist the Fundraiser with data protection impact assessments, cooperation with supervisory authorities, and security incident notifications.
Payaz shall indemnify and hold harmless the Fundraiser against direct losses or damages resulting from proven breaches of this DPA caused by Payaz’s failure to comply with its obligations, subject to any limitations in the Terms. Neither party will be liable for indirect or consequential losses.
This DPA remains in force for the duration of the Terms. Upon termination of the Terms, this DPA shall automatically terminate following the deletion of all Donation Data in accordance with Section 7.
This DPA shall be governed by and construed in accordance with the laws of Northern Ireland, and the parties submit to the exclusive jurisdiction of the courts of Northern Ireland.
Sub-Processor | Purpose | Region |
Google (Firebase) | Hosting and storage | EU |
Stripe | Payment processing | EU/UK |
SumUp | Payment processing | EU/UK |