for merchant

DATA PROCESSING AGREEMENT

March 15, 2024

Merchant and EBANX are hereinafter referred to jointly as “Parties” or, individually, as “Party”.

This Data Processing Agreement (“Agreement”) applies to activities involving the Processing of Personal Data (as defined below) performed in connection with the Contract and is an integral part of the Contract for all legal purposes.

Any capitalized terms not otherwise defined in this Agreement shall have the meaning given thereto in the Contract or in the Brazilian General Data Protection Act - LGPD. Except as modified below, the terms of the Contract shall remain in full force and effect.

The provisions in Clauses 2 to 9 are applicable when contracting EBANX Payment Services. Services in which EBANX acts as Processor, while the Merchant acts as Controller.

The provisions in Clauses 10 to 18 are applicable when using EBANX Anti-Fraud Services. Services in which EBANX and the Merchant act as sole controllers (i.e. independent controllers).

The provisions in clauses 1 and 19 to 21 are applicable regardless of the service contracted or used.


1. Definitions

In this Agreement, the following terms shall have the meanings defined below:

“Data Protection Laws and Regulations” means any law and regulation, including any decision published by any competent Government Authority, applicable to the Processing of Personal Data carried out within the context of the Contract.

“Controller’s Personal Data” means any Personal Data shared by the Controller to the other Party or any of their Processors for processing purposes, including Sensitive Personal Data, in the context of the Agreement.

“Data Processing” means any operation carried out with Personal Data, such as collection, production, receipt, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, deletion, evaluation or control of the information, modification, communication, transfer, dissemination or extraction.

“Services” means the services and other activities that will be provided or performed by or on behalf of the Processor for the Controller Party pursuant to the Contract;

“Subprocessor” means any natural or legal person who, on behalf of the Processor, will process Personal Data on behalf of the Controller under the Contract.

"Employee(s)” means any employee, worker, including subcontractors or outsourced staff, representatives or designees, remunerated or not, under a full or partial regime, who act on behalf of the Parties and have access to the Personal Data.

“Government Authorities” means any authority, including judicial, vested with powers to inspect, judge and apply pertinent laws, including, without limitation, the ANPD.

“Security Incident” means any adverse security event or set of events, confirmed or suspected that impacts the availability, integrity, confidentiality or authenticity of an information asset. In the case of this Agreement, the expression will refer to incidents involving Personal Data.

“End Date” has the meaning described in section 9 and 18, where it applicable.

PAYMENT SERVICES – PROCESSOR (EBANX) X CONTROLLER (MERCHANT) RELATIONSHIP

The clauses agreed below will solely be, and will be exclusively, applicable in the case of contracting EBANX Payment Services.


2. Processing of the Controller’s Personal Data

The performance of the Contract presupposes the sharing of Personal Data from the Controller to the Processor. With regard to activities involving the Processing of Personal Data pursuant to the context of the Contract, the Processor shall:

Ensure the confidentiality of the Controller's Personal Data, by itself and its Collaborators who may have access to it; and

Process Personal Data in accordance with all applicable Data Protection Laws and Regulations, including those in force after the signing of this Agreement, and in accordance with the Controller's instructions, except in cases where the Processing is necessary for compliance with legal or regulatory obligations to which the Processor is subject, or for carrying out the Processor's business activities, in accordance with the Data Protection Laws and Regulations.

If the Processor performs any Processing activity unrelated to the performance of the Contract, said Processing activity shall occur outside the context of this Agreement. The Processor shall be deemed the sole Controller in relation to that activity, and the Controller shall be released from any obligation or liability derived therefrom.

The Controller shall:

Make the Personal Data available so that the Processor can perform the contracted Services, ensuring that the Personal Data has been collected in accordance with the provisions and principles of the Data Protection Laws and Regulations, and especially that the processing intended by the Controller is duly grounded on one of the legal basis set out by the Data Protection Laws and Regulations;

Provide the Processor with all the necessary instructions for carrying out the Personal Data Processing activities that need to be performed in the context of the Contract;

Promptly inform the Processor whenever there are changes or inaccuracies in the Personal Data; and

Cooperate with the Processor, where applicable, in the fulfillment of requests regarding the rights of data subjects provided for in the Data Protection Laws and Regulations, and also to comply with any requests from Government Authorities.


3. Security

The Processor shall implement appropriate technical, administrative and organizational measures compatible with the Processing activities performed. To assess the appropriate level of security, the Processor shall consider the risks posed by the Processing activity, in particular those related to Security Incidents.


4. Subprocessor

The Processor may, when necessary for the performance of the Personal Data Processing activities, hire Subprocessors to assist it in the performance of the Contract.

The Processor must, when carrying out any Processing activity through a Subprocessor, ensure, through a specific contract signed with the Subprocessor, a security level equivalent to this Agreement.


5. International Data Transfers

If an international Data transfer, by the Processor, is necessary for performance of the Contract, and the country of destination does not have an appropriate level of protection for Personal Data in accordance with the Government Authorities determinations, then the Processor shall ensure that the international Data transfer will be made pursuant to one of the mechanisms contemplated in the Data Protection Laws and Regulations. 


6. Rights of Data Subjects

The Processor undertakes to notify the Controller in the event of receiving a request from a Data Subject in connection with any Processing activity carried out on behalf of the Controller in the context of the Agreement, so that the Controller may take appropriate action.


7. Security Incident

The Processor shall notify the Controller when it identifies the existence of a Security Incident that may entail material risk or harm to the Data Subjects and, if necessary, will provide sufficient information to enable the Controller to comply with any requirements under Data Protection Laws and Regulations.

The Controller shall not disclose any information concerning the Security Incident, unless otherwise authorized by the Processor or required by determination of the Government Authorities or by Data Protection Laws and Regulations.

If the Controller is responsible for the Security Incident, it shall indemnify the Processor for all costs incurred during the investigation of the incident and in relation to all actions taken by the Processor to respond to or minimize the impacts of the Security Incident.


8. Government Authorities

The Processor shall inform the Controller if it receives requests for information or determinations by the Government Authorities in relation to any Processing activity carried out in the context of the Contract, so that the Controller may take the appropriate measures.


9. Exclusion and return of Personal Data

Upon termination of the Contract, the Processor shall, when requested in writing by the Controller, return or delete the Personal Data processed on behalf of the Controller, and may retain Personal Data that is necessary for compliance with legal or regulatory obligations to which the Processor is subject, or for carrying out the Processor's  business activities, in accordance with the Data Protection Laws and Regulations.


ANTI-FRAUD SERVICES – CONTROLLER (EBANX) X CONTROLLER (MERCHANT) RELATIONSHIP

The clauses set out below will only be, and will be exclusively, applicable in the case of contracting EBANX Anti-Fraud Services.


10. Processing of Personal Data

He performance of the Contract presupposes the sharing of Personal Data between both Parties. The Parties agreed with regard to activities involving the Processing of Personal Data pursuant to the context of the Contract:

Process the Personal Data in accordance with all applicable Data Protection Laws and Regulations, including those coming into force after the signing of this Agreement, ensuring in particular that every Processing activity be duly justified on one of the legal bases established by the Data Protection Laws and Regulations. 

Process only the Personal Data necessary for execution of the Contract, in accordance with Appendix 1 (when filled out) and solely for the purposes of the Contract, except if the Processing is required for fulfillment of legal or regulatory obligations to which EBANX is subject. 

If the EBANX has access, in the context of the Contract, to Personal Data that it considers excessive or not necessary for the execution of the Contract, it shall immediately notify the other Party and disable such Personal Data. 

If the EBANX performs any Processing activity unrelated to the performance of the Contract, said Processing activity shall occur outside the context of this Agreement. The Party which execute the processing shall be deemed the sole Controller in relation to that activity, and the other Party shall be released from any obligation or liability derived therefrom. 

Mutually cooperate to ensure proper compliance with the obligations relating to the exercise of Data Subject's rights under the Data Protection Laws and Regulations, and fulfillment of any requests from the Inspection Authorities, within the limit of their activities. 

The Parties shall not use any type of tool, technology, reverse engineering or other method intended to identify the Data Subjects, where Personal Data was shared in a manner that does not permit direct identification of the Data Subjects without cross-checking with other information or with access to the identification key.


11. Employees

The Parties shall ensure that the Processing of Personal Data performed in the context of the Contract will be restricted to the Employees responsible for the Processing, in accordance with section 10.1.2 of this Agreement, and that such Employees:

Have received training in connection with data protection principles and processing laws; and

Know the obligations of the Parties, including the obligations contemplated in this Agreement.

The Parties shall ensure that all Employees are subject to confidentiality agreements or professional or statutory obligations of confidentiality and data protection.


12. Security

Each Party shall implement appropriate technical, administrative and organizational measures compatible with the Processing activities performed. To assess the appropriate level of security, the Parties shall consider the risks posed by the Processing activity, in particular those related to Security Incidents.

The Parties may establish, in writing, minimum security criteria which they deem necessary for performance of the Contract and which shall be adopted by the Parties.

The Parties undertake to regularly test, assess and evaluate the effectiveness of the technical, administrative and organizational measures for ensuring security of the operations involving the Processing of Personal Data.


13. Subcontractors

When any Processing Activity is carried out through a Subcontractor, whether Controller or Processor, the Parties must, in relation to these Subcontractor:

Preserve the integrity and accuracy of Personal Data, and must update, correct or delete such data at the request of the other Party;

Verify, through due diligence or equivalent procedure, that each Subcontractor is able to guarantee a level of Personal Data protection, at least, equivalent to this Term and provide evidence of this verification;

Enter into a formal Agreement with each Subcontractor, which the content must include provisions, at least, equivalent to this Term; and

Be responsible for all actions and omissions of the Subcontractor in relation to the processing of Personal Data.


14. International Data Transfers

If an international Data transfer is necessary for performance of the Contract, and the country of destination does not have an appropriate level of protection for Personal Data in accordance with the Authorities determinations, then the EBANX shall ensure that the international Data transfer will be made pursuant to one of the mechanisms contemplated in the Data Protection Laws and Regulations and related Data Protection Laws and Regulations. 


15. Rights of Data Subjects

The Parties shall mutually cooperate with in complying with the obligations related to the exercise of Data Subject's rights, in consonance with Data Protection Laws and Regulations.

The Parties shall:

Immediately notify the other Party upon receiving a request from the Data Subject, when related to any Processing activity performed under the Contract; and

Refrain from responding to any Data Subject's request related to the Personal Data of the other Party until this Party provides its written agreement with the contents of the response to be presented to the Data Subject, except where the timeframe for responding to the request is shorter than 48 hours, in accordance with the Data Protection Laws and Regulations.  


16. Security Incident

When a Party identifies the occurrence of a Security Incident that may cause  material damage to the Data Subject, in accordance with the Data Protection Laws and Regulations and any regulations that may be issued by the applicable Government Authorities, this Party shall immediately notify the other Party. This notice shall include sufficient information (containing at least a description of the event, date, cause, possible impacts on the Data Subjects to whom the Personal Data relate, mitigation actions adopted, and next steps) so that the interested Party can comply with any requirements imposed by Data Protection Laws and Regulations.

The Parties shall at its own expense investigate the causes and consequences of the Security Incident, and take the necessary measures to remedy its consequences, promptly informing the Parties about all measures so taken.

The Parties shall maintain records on the Security Incident, including at least (a) a description of the nature of the Security Incident, (b) a description of the consequences of the Security Incident, and (c) a description of the measures taken or proposed by the other Party to cope with the Security Incident.

The Parties shall not disclose any information concerning the Security Incident, unless otherwise authorized by the Contracting Party or required by determination of the Government Authorities, pursuant to Brazilian law.


17. Government Authorities

The Parties shall mutually cooperate in complying with obligations or requests imposed by any competent Government Authority.

The Parties shall forthwith inform the other Party upon receiving requests for information or determinations from the Government Authorities relating to any Processing activity performed within the context of the Contract. If such requests or determinations are related to the Personal Data shared by the other Party, then the Party subpoenaed shall submit a suggestion of answer for the other Party's validation within the time period prescribed by law or determined by the Government Authorities.


18. Exclusion and return of Personal Data

Each Party, when the activities involving the Processing of Personal Data within the context of the Contract are finished (“End Date”), the shall interrupt the processing of the Personal Data of the other Party and, upon written request, shall delete the Personal Data relating to the completed activities, as well as all existing copies (in digital or physical form), unless maintenance of the Personal Data is necessary for complying with a legal or regulatory obligation.

The Parties may, at its sole discretion, by giving written notice to the other Party, within 30 calendar days from the End Date, require that the other Party return a full copy of all Personal Data processed under the Contract, via a secure transfer and interoperable or proprietary format for the other Party. 

The Parties shall provide the other Party with written certification that they have fully complied with this section within 30 calendar days from the End Date.


GENERAL CLAUSES APLICABLE FOR ANY SERVICES PROVIDED BY EBANX

The provisions in clauses 1 and 19 to 21 are applicable regardless of the service contracted.


19. Indemnification

The Parties shall indemnify, defend and exempt the other Party and/or its affiliates from and against any liability, loss, claim, damage, fine, penalty and expense (including, without limitation, fines, compensation for damage, costs incurred with reparation efforts, and attorneys' fees and costs resulting from or relating to any suit, claim or allegation of third parties, including, without limitation, any regulatory or governmental authority) arising out of noncompliance with this Agreement and/or with the Data Protection Laws and Regulations.

If any Government Authorities imputes sanctions to the Parties in connection with this Agreement, and if verified negligence, willful misconduct or other liability of the other Party, then this Party shall pay the financial penalty – when applicable - and/or indemnify the innocent Party, including for damage to reputation suffered, in addition to costs and expenses incurred in the course of the administrative proceeding. 

This Agreement does not create joint liability between the Parties for any penalties relating to the Processing activities performed under the Contract, so each Party shall be held severally liable within the limit of its activities.


20. Liability

The indemnification obligations agreed on this Term, shall be additional to, and not in exclusion of, any indemnification obligation appearing in the Contract.

It is also established that this Agreement: (i) does not result in any limitation of liability or obligation to indemnify of the EBANX by reason of the Processing of Personal Data performed under the Contract; and (ii) does not prevent the Contracting Party from exercising any rights it may have in relation to this Agreement.


21. General Provisions

Without prejudice to any provisions regarding mediation and jurisdiction:

The Parties hereto submit to the choice of the jurisdiction stipulated in the Contract in connection with any disputes or claims that may in any way result from this Agreement, including disputes relating to its existence, validity or termination or the consequences of its nullity; and

This Agreement and all extracontractual obligations or other obligations arising out of or relating to this Agreement shall be governed by the laws of the country or territory stipulated for this purpose in the Contract.

In the event of conflict between the provisions of this Agreement and the Contract or any other document performed between the parties, specifically in connection with activities involving the Processing of Personal Data, the provisions of this Agreement shall prevail, except where a supervening document is executed between the parties, expressly declaring the subsidiary nature of this Agreement.

This Agreement may be amended at the discretion of the parties or in the event of a supervening law or regulation or determinations on the part of any Government Authority requiring a change in its provisions. The new provisions shall be agreed upon in good faith by the Parties and always in writing in the form of an amendment to this Agreement.

If any provision of this Agreement is held void, invalid or unenforceable, the remaining provisions hereof shall remain in full force and effect. The void, invalid or unenforceable provision shall be amended to ensure its validity and effectiveness, while preserving the intention of the Parties.

This Agreement shall remain in effect until termination of the Contract for any reason.

This Agreement shall survive the expiration of the Contract and continue to bind the Parties in relation to activities involving the Processing of Personal Data of the Contracting Party which originate from the Contract and continue to be performed, though only for purposes of complying with a legal or regulatory obligation.

This Agreement is performed and becomes an integral and mandatory part of the Contract, with effects as from the date hereof, applying, however, to all activities regarding the processing of Personal Data performed since the date of performance of the Contract.