Data Processing Addendum

Our processor terms, including the EU Standard Contractual Clauses.

Last updated 20 August 2026

How this DPA applies to you

This Data Processing Addendum, including its annexes (this "DPA"), forms part of the Paidnice Terms of Service (the "Agreement") between you ("Customer", "you") and Paidnice Limited ("Paidnice", "Provider", "we", "us"), a company incorporated in New Zealand at Suite 14537, 17B Farnham Street, Parnell, Auckland 1052, New Zealand.

No signature is required. This DPA is incorporated into the Agreement by reference and takes effect automatically when you accept the Agreement. It applies to every Paidnice customer worldwide. If your organisation requires a countersigned copy for its own records, email [email protected] and we will provide one.

This DPA applies where Paidnice Processes Personal Data on your behalf, in the role described in section 2 of our Privacy Policy. It does not apply to Personal Data for which Paidnice is itself the Controller, such as your own account and billing details. That Processing is governed by the Privacy Policy.

Where there is a conflict, this DPA prevails over the Agreement. The Standard Contractual Clauses referred to in Annex 2 prevail over both, for the Restricted Transfer to which they apply.

1. Definitions

Capitalised terms not defined here have the meaning given in the Agreement.

  • Affiliate means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where "control" refers to the power to direct or cause the direction of the subject entity, whether through ownership of voting securities, by contract or otherwise.
  • Applicable Data Protection Laws means the privacy, data protection and data security laws and regulations applicable to Provider's Processing of Personal Data under the Agreement, including, as and to the extent applicable, the NZ Privacy Act, the Australian Privacy Act, the State Privacy Laws and the GDPR.
  • Australian Privacy Act means the Privacy Act 1988 (Cth), including the Australian Privacy Principles and the Notifiable Data Breaches scheme.
  • Controller means the entity that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data, including, as applicable, any "business" or "controller" as such term is defined by the California Consumer Privacy Act (the "CCPA") or other State Privacy Laws, and any "agency" as that term is defined in the NZ Privacy Act.
  • Customer Data means information provided or otherwise made available by or on behalf of Customer to Provider for Processing on Customer's behalf to perform the Services, including data synchronised from an accounting platform Customer connects to the Services.
  • Data Subject means the identified or identifiable natural person to whom Personal Data relates.
  • EEA means the European Economic Area.
  • FADP means the Swiss Federal Act on Data Protection of 25 September 2020 (as amended and in force from 1 September 2023) and any applicable implementing legislation and ordinances, and, to the extent applicable, its predecessor of 19 June 1992.
  • FDPIC means the Swiss Federal Data Protection and Information Commissioner.
  • GDPR means, as and where applicable to the Processing concerned: (i) the General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"); and/or (ii) the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (as amended) ("UK GDPR"), including in each case any applicable national implementing or supplementary legislation (for example the UK Data Protection Act 2018), and any successor, amendment or re-enactment. References to "Articles" and "Chapters" of, and other defined terms in, the GDPR are construed accordingly.
  • Information Security Incident means a breach of Provider's security resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data in Provider's possession, custody or control. Information Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.
  • NZ Privacy Act means the Privacy Act 2020 (New Zealand), as amended, including by the Privacy Amendment Act 2025, and the information privacy principles set out in it.
  • OPC means the New Zealand Office of the Privacy Commissioner.
  • Personal Data means Customer Data that constitutes "personal data", "personal information", or "personally identifiable information" as defined in Applicable Data Protection Laws, or information of a similar character regulated by them. Personal Data does not include information pertaining to Customer's business contacts who are Customer personnel, or information that Provider receives, collects, or generates independently of the Services and not from or on behalf of Customer.
  • Process or Processing means any operation or set of operations performed by Provider, or on Provider's behalf, for Customer under the Agreement on Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • Processor means the entity that Processes Personal Data on behalf of the Controller, including, as applicable, any "service provider" or "contractor" as those terms are defined by the CCPA, and any "agent" for the purposes of section 11 of the NZ Privacy Act.
  • Restricted Transfer means the disclosure, grant of access or other transfer of Personal Data to any person located in: (i) in the context of the EEA, any country or territory outside the EEA which does not benefit from an adequacy decision from the European Commission (an "EU Restricted Transfer"); (ii) in the context of the UK, any country or territory outside the UK which does not benefit from an adequacy decision from the UK Government (a "UK Restricted Transfer"); and (iii) in the context of Switzerland, a country or territory outside Switzerland which does not benefit from an adequacy decision from the Swiss Government (a "Swiss Restricted Transfer"), in each case which would be prohibited without a legal basis under applicable data protection law, including Chapter V of the GDPR where applicable.
  • SCCs means the standard contractual clauses approved by the European Commission pursuant to implementing Decision (EU) 2021/914.
  • Security Measures has the meaning given in section 4(a).
  • Services has the meaning given in the Agreement.
  • State Privacy Laws means, collectively, the comprehensive state-specific data privacy laws of the United States, and any implementing regulations, currently in effect and applicable to Provider's Processing of Personal Data under the Agreement.
  • Subprocessors means Provider's Affiliates and third parties that Provider engages to Process Personal Data in relation to the Services.
  • Supervisory Authority means any entity with the authority to enforce Applicable Data Protection Laws, including (i) in the context of the EEA and the EU GDPR, the meaning given to that term in the EU GDPR; (ii) in the context of the UK and the UK GDPR, the UK Information Commissioner's Office; (iii) in the context of Switzerland and the FADP, the FDPIC; (iv) in the context of New Zealand, the OPC; and (v) in the context of Australia, the Office of the Australian Information Commissioner ("OAIC").
  • UK Transfer Addendum means the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as revised under Section 18 of the Mandatory Clauses included in Part 2 of it.

2. Duration and scope

This DPA remains in effect for as long as Provider Processes Personal Data, whether or not the Agreement has expired or been terminated.

Processing of Personal Data subject to the GDPR is also subject to Annex 2 (European Annex).

Processing of Personal Data subject to the State Privacy Laws, where Customer is a Business, Controller, Processor, or Service Provider as those terms are defined in the State Privacy Laws, is also subject to Annex 3 (State Privacy Laws Annex).

Processing of Personal Data subject to the NZ Privacy Act or the Australian Privacy Act is also subject to Annex 6 (New Zealand and Australia Annex).

3. Customer instructions

Provider will Process Personal Data only in accordance with Customer's documented instructions, including as set out in this DPA, the Agreement, any applicable order form, and any other written instructions Customer provides from time to time that are consistent with the Agreement and this DPA. Where Customer requests instructions that are outside the scope of the Services, or that would require Provider to materially change the Services or undertake additional work not contemplated by the Agreement, the parties will agree those instructions in a mutually executed amendment to this DPA or other written agreement.

By entering into this DPA, Customer instructs Provider to Process Personal Data to provide the Services and to perform Provider's other obligations and exercise its rights under the Agreement. This includes sending invoice reminders, statements, late fee notices, payment plan communications and payment links to Customer's own customers by email, SMS or automated voice call, in each case as configured by Customer. The details of Provider's Processing, including the roles of the parties, are described in Annex 1.

4. Security

(a) Provider Security Measures. Provider will implement and maintain technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data, as described in Annex 4 (the "Security Measures"), taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing and the risks to Data Subjects. Provider may update the Security Measures from time to time, including to maintain or improve security or to address changes in Applicable Data Protection Laws, so long as the updated measures do not materially decrease the overall protection of Personal Data. Further detail is published on our Security and Trust page.

(b) Security compliance by Provider staff. Provider will require that its personnel who are authorised to access Personal Data are subject to appropriate confidentiality obligations.

(c) Information Security Incidents. Provider will notify Customer without undue delay of any Information Security Incident of which Provider becomes aware. The notification will describe, to the extent then known, available details of the Information Security Incident, including steps taken to mitigate the potential risks and steps Provider recommends Customer take. Provider's notification of, or response to, an Information Security Incident will not be construed as an acknowledgement of fault or liability. Provider will reasonably cooperate with Customer and take such commercially reasonable steps, to the extent within Provider's control, as Customer reasonably requests and the parties agree in good faith, to assist in the investigation.

Customer is solely responsible for complying with notification laws applicable to Customer and for fulfilling any third-party notification obligations related to any Information Security Incident. If Customer determines that an Information Security Incident must be notified to any Supervisory Authority, any Data Subject, the public or others under Applicable Data Protection Laws, and that notice directly or indirectly refers to or identifies Provider, then where permitted by applicable law Customer agrees to (i) notify Provider in advance, and (ii) consult with Provider in good faith and consider any clarifications or corrections Provider reasonably recommends that relate to Provider's involvement in the Information Security Incident and are consistent with applicable law.

5. Customer security responsibilities and assessment

(a) Customer's security responsibilities. Without limiting Provider's obligations under section 4, Customer is solely responsible for its use of the Services, including (i) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Personal Data; (ii) securing the account authentication credentials, systems and devices Customer uses to access the Services, including enabling multi-factor authentication where available; (iii) securing Customer's systems and devices that Customer provides or makes available for Provider to access in order to provide the Services, including any connected accounting platform; and (iv) backing up Personal Data, as applicable.

(b) Customer's security assessment. Customer acknowledges that it has evaluated the Services, the Security Measures and Provider's commitments under this DPA and, based on information made available by Provider, determines that they are adequate to meet Customer's needs, including any security obligations of Customer under Applicable Data Protection Laws, and provide a level of security appropriate to the risk in respect of the Personal Data.

6. Data Subject rights

(a) Assistance. Provider will, taking into account the nature of the Processing, provide Customer with assistance reasonably necessary and technically feasible for Customer to perform its obligations under Applicable Data Protection Laws to fulfil requests by Data Subjects to exercise their rights ("Data Subject Requests") with respect to Personal Data in Provider's possession or control. Customer will compensate Provider for such assistance, to the extent it requires work beyond the Services, at Provider's then-current professional services rates, which Provider will make available on request. Provider will, on request, provide a good-faith estimate of applicable fees.

(b) Customer responsibility for requests. If Provider receives a Data Subject Request, Provider will (i) promptly notify Customer, unless prohibited by applicable law; and (ii) advise the Data Subject to submit the request to Customer. Customer is solely responsible for responding to any such request, unless otherwise required by applicable law.

7. Customer responsibilities

(a) Notices and consents. Customer will ensure, and is solely responsible for ensuring, that it has provided all notices to, and obtained all consents and permissions from, third parties including Data Subjects, and has reserved all necessary rights, in each case as required under Applicable Data Protection Laws for Provider to Process Personal Data as contemplated by the Agreement.

(b) Contacting Customer's own customers. The Services send communications to Customer's own customers on Customer's behalf. Customer is solely responsible for ensuring it holds every notice, consent, registration and lawful basis required to contact those recipients by email, SMS and automated voice call, and to record any call, under the laws of each recipient's jurisdiction. Section 6A of the Agreement sets out Customer's warranties and indemnity on this point, and applies in full to this DPA.

(c) Restricted Data. Customer represents and warrants that Customer Data does not and will not contain: government-issued identification numbers; protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA) or other information about an individual's medical history, mental or physical condition, or medical treatment or diagnosis; health insurance information; biometric information; passwords or other credentials for third-party online accounts, other than credentials created for and used solely to access the Services; credentials to any financial accounts; any payment card information subject to the Payment Card Industry Data Security Standard; Personal Data of children under 16 years of age; or any other information that falls within any special category of data as defined in Applicable Data Protection Laws ("Restricted Data").

This warranty does not apply to information that is inherently contained in invoice, contact and accounting records synchronised from Customer's connected accounting platform in the ordinary course, such as a business tax registration number printed on an invoice. Customer remains responsible for not entering Restricted Data into free-text fields, message templates, custom fields or attachments.

(d) Lawful basis. Customer will ensure that there is, and will be throughout the term of the Agreement, a valid legal basis for Provider's Processing of Personal Data in accordance with this DPA and the Agreement, including any instruction Customer issues, as required under all Applicable Data Protection Laws, including where applicable Articles 6, 9(2) and 10 of the GDPR.

(e) Data Subject notices. Customer will ensure that all Data Subjects have (i) been presented with all required notices and statements, including as required by Articles 12 to 14 of the GDPR where applicable and by information privacy principle 3A of the NZ Privacy Act; and (ii) provided all required consents, in each case relating to Provider's Processing of Personal Data.

8. Subprocessors

(a) Consent to engagement. Customer specifically authorises the engagement of Provider's Affiliates as Subprocessors, and generally authorises Provider to engage third parties as Subprocessors in accordance with this section 8.

(b) Information about Subprocessors. Information about Subprocessors, including their functions and locations, is published at www.paidnice.com/sub-processors (the "Subprocessor Site") and reproduced in Annex 5. Provider may continue to use those Subprocessors already engaged as at the effective date of this DPA.

(c) Requirements for engagement. When engaging any Subprocessor, Provider will enter into a written contract with that Subprocessor containing data protection obligations not less protective than those in this DPA with respect to Personal Data, to the extent applicable to the nature of the services provided. Provider remains responsible for the performance of all obligations subcontracted to the Subprocessor and is liable for all acts and omissions of the Subprocessor to the same extent as if Provider had performed the Processing itself.

(d) Opportunity to object. When Provider engages a new Subprocessor after the effective date of this DPA, Provider will notify Customer of the engagement, including the name and location of the Subprocessor and the activities it will perform, by updating the Subprocessor Site and by written notice, including by email, to Customer's designated contact for Services-related communications. If Customer objects within 15 days after receipt of that notice, in writing and on reasonable grounds relating to the protection of Personal Data, the parties will work together in good faith to find a mutually acceptable resolution. If the parties cannot reach one within a reasonable timeframe, Customer may, as its sole and exclusive remedy, terminate the Agreement and cancel the Services by written notice, and must pay all amounts due and owing under the Agreement as at the date of termination.

9. Audits

Customer may audit Provider's compliance with its obligations under this DPA up to once per year, and on such other occasions as may be required by Applicable Data Protection Laws solely to the extent Customer is legally required to conduct the additional audit or a competent Supervisory Authority with jurisdiction over Customer requires it, in each case on Customer's written request providing reasonable detail and, where available, supporting documentation of the applicable requirement. Provider will contribute to the audit by providing the information and assistance reasonably necessary to conduct it.

If a third party is to conduct the audit, Provider may object to the auditor if, in Provider's reasonable opinion, the auditor is not independent, is a competitor of Provider, or is otherwise manifestly unsuitable. Such an objection requires Customer to appoint another auditor or conduct the audit itself. To request an audit, Customer must submit a proposed audit plan at least two weeks before the proposed audit date, and any third-party auditor must sign a customary non-disclosure agreement acceptable to both parties, such acceptance not to be unreasonably withheld, providing for confidential treatment of all information exchanged and any report of the results. The proposed audit plan must describe the proposed scope, duration, and start date. Provider will review the plan and raise any concerns or questions, for example any request for information that could compromise Provider's security, privacy, employment or other relevant policies, and the parties will work cooperatively to agree a final plan. Nothing in this section requires Provider to breach any duty of confidentiality.

If the controls or measures to be assessed are addressed in a SOC 2 Type 2, ISO, NIST or similar audit report performed by a qualified third-party auditor within 12 months of Customer's audit request, and Provider has confirmed there have been no known material changes in the controls audited since the date of that report, Customer agrees to accept that report in place of an audit of those controls or measures.

The audit must be conducted during regular business hours, subject to the agreed final audit plan and Provider's safety, security and other relevant policies, and must not unreasonably interfere with Provider's business activities. Customer will promptly notify Provider of any non-compliance discovered, and provide Provider any audit report generated, unless prohibited by Applicable Data Protection Laws. Customer may use audit reports only to meet its regulatory audit requirements or to confirm compliance with this DPA. Audits are at Customer's sole expense. Customer will reimburse Provider for any reasonable, documented costs, including reasonable internal time expended by Provider and any third parties, at Provider's then-current professional services rates, which Provider will make available on request. Customer is responsible for any fees charged by any auditor it appoints.

10. Return and deletion

(a) Subject to sections 10(b) and 10(c), on the date of cessation of any Services involving the Processing of Personal Data (the "Cessation Date"), Provider will promptly cease all Processing of Personal Data for any purpose other than storage and Processing necessary to effect the return, deletion, or anonymisation of that Personal Data, or as otherwise permitted or required under this DPA or applicable law.

(b) Subject to section 10(d), to the extent technically feasible in the circumstances, on written request to Provider made within 30 days after the Cessation Date (the "Post-cessation Storage Period"), Provider will, within a commercially reasonable period following receipt of the request and as elected by Customer, either (i) return a complete copy of all Personal Data within Provider's possession to Customer by secure file transfer or other commercially reasonable secure method, and promptly after that delete or anonymise all other copies, or (ii) delete or anonymise all Personal Data within Provider's possession.

(c) If, during the Post-cessation Storage Period, Customer does not instruct Provider in writing under section 10(b), Provider will, within a commercially reasonable time after the expiry of that period, at its option delete or anonymise all Personal Data then within its possession, custody or control, to the fullest extent technically feasible.

(d) Provider may retain Personal Data to the extent permitted or required by applicable law, for no longer than that law requires, provided Provider will (i) maintain the confidentiality of that Personal Data and protect it in accordance with the Security Measures; (ii) Process it only as necessary for the purpose specified in the law permitting or requiring retention; and (iii) delete or anonymise it once retention is no longer permitted or required.

11. Artificial intelligence and automated Processing

(a) Provider will not use Personal Data to train, fine-tune, develop, or improve any artificial intelligence or machine learning model, whether Provider's own or a third party's, unless (i) the use is reasonably necessary to provide the Services in accordance with Customer's documented instructions, or (ii) Customer expressly authorises it in writing.

(b) Provider will prohibit its Subprocessors, including any artificial intelligence model providers, from using Personal Data for their own model training, fine-tuning, development, or improvement purposes, except as Customer expressly authorises in writing.

(c) Where the Services include automated voice calls placed to Customer's own customers, Provider discloses that those calls are generated and conducted by an artificial intelligence system. Customer is responsible for the disclosures, notices and consents required in each recipient's jurisdiction, as set out in section 7(b) of this DPA and section 6A of the Agreement.

(d) If the Services involve automated decision-making that produces legal or similarly significant effects on Data Subjects, Provider will (i) disclose the existence of that Processing to Customer; (ii) to the extent reasonably available to Provider, provide meaningful information about the logic involved, without requiring disclosure of Provider's trade secrets or confidential information; and (iii) reasonably cooperate with Customer, as required by Applicable Data Protection Laws, to enable Data Subjects to exercise applicable rights relating to automated decision-making.

12. Miscellaneous

(a) Except as expressly modified by this DPA, the terms of the Agreement remain in full force and effect. Despite anything in the Agreement or any order form to the contrary, the parties agree that Provider's access to Personal Data does not form part of the consideration exchanged under the Agreement. Any notice Provider is required or permitted to give Customer under this DPA may be given (i) in accordance with any notice clause of the Agreement; (ii) to Customer's contact details for data protection set out in Annex 1; (iii) to Provider's primary points of contact with Customer; or (iv) to any email address Customer designates in writing for receiving Services-related communications or alerts. Customer is solely responsible for ensuring those email addresses are valid.

(b) Provider will cooperate in good faith with Customer to consider any amendment reasonably necessary to address compliance with Applicable Data Protection Laws.

(c) Provider may, on written notice, vary this DPA solely to the extent necessary to maintain compliance with Applicable Data Protection Laws from time to time, provided the variation does not materially reduce the protections afforded to Personal Data or materially increase Customer's obligations without Customer's written agreement. This includes varying or replacing the SCCs in accordance with paragraph 3.4 of Annex 2.

(d) Liability. To the extent permitted by Applicable Data Protection Laws and the SCCs, if and as they apply, the total aggregate liability of either party to the other, however arising, under or in connection with this DPA and the SCCs, will not exceed the limitations or caps on, and is subject to the exclusions of, liability and loss agreed by the parties in the Agreement. Nothing in this section 12(d) affects any person's liability to Data Subjects under the third-party beneficiary provisions of the SCCs, if and as they apply.

(e) Order of precedence. If there is any conflict or inconsistency between (i) this DPA and the Agreement, this DPA prevails; or (ii) any SCCs entered into under paragraph 3 of Annex 2 and this DPA or the Agreement, the SCCs prevail in respect of the Restricted Transfer to which they apply.

(f) Governing law. This DPA is governed by the laws of New Zealand, and section 14 (Governing Law) and section 12 (Dispute Resolution) of the Agreement apply to it. This does not affect the governing law and forum of the SCCs themselves, which are set by paragraph 3 of Attachment 1 to Annex 2 as required for those clauses to remain valid.

Annex 1: Data Processing Details

Provider / data importer

  • Name: Paidnice Limited
  • Address: Suite 14537, 17B Farnham Street, Parnell, Auckland 1052, New Zealand
  • Contact details for data protection: Privacy Officer, [email protected]
  • Provider activities: Paidnice provides accounts receivable automation software that connects to a customer's accounting platform to send invoice reminders, statements, late fees, payment plans and payment links, and to report on receivables.
  • Role: Processor, or Subprocessor as applicable.

Customer / data exporter

  • Name: the entity or other person who is a counterparty to the Agreement.
  • Address: as recorded in Customer's Paidnice account.
  • Contact details for data protection: as recorded in Customer's Paidnice account, or as notified to Provider in writing.
  • Customer activities: the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement, as part of Customer's ongoing business operations.
  • Role: Controller, or Processor as applicable.

Categories of Data Subjects: any Data Subjects whose Personal Data Customer causes Provider to Process in connection with the Services, including Customer's own customers and debtors and their staff and representatives, and Customer's personnel, including employees and contractors, and other business contacts or representatives of Customer.

Categories of Personal Data: any categories of Personal Data Customer causes Provider to Process as part of the provision of the Services, including:

  • Personal details, for example any information that identifies the Data Subject, including name, business name, email address, phone number and postal address.
  • Transactional details, for example invoice numbers, amounts, due dates, payment status, credit notes, statements and related notes synchronised from Customer's accounting platform.
  • Communication records, for example the content, delivery status and timestamps of reminder emails, SMS messages and automated voice calls sent through the Services, and any transcript or recording of those calls where that feature is enabled.
  • Authentication details, for example usernames, security questions, authentication tokens, and other access protocols used to access the Services.
  • Technological details, for example internet protocol (IP) addresses, unique identifiers and numbers including identifiers in cookies or similar technology, pseudonymous identifiers, imprecise location data, application activity data, and device identifiers.

Sensitive categories of data: none. As set out in section 7(c), Customer agrees that Restricted Data, which includes "sensitive data" as defined in Clause 8.7 of the SCCs, must not be submitted to the Services without the parties' prior written agreement.

Additional safeguards for sensitive data: not applicable.

Frequency of transfer: ongoing, as initiated by Customer in and through its use of the Services, or use on its behalf.

Nature of the Processing: Processing operations required in order to provide the Services and perform Provider's obligations in accordance with the Agreement and this DPA.

Purpose of the Processing: as necessary to provide the Services as initiated by Customer in its use of them, and to comply with Customer's documented instructions as permitted under and in accordance with this DPA and the Agreement.

Duration of Processing and retention period: for the period determined in accordance with the Agreement and this DPA, including section 10.

Transfers to Subprocessors: transfers to Subprocessors are as, and for the purposes, described from time to time on the Subprocessor Site and in Annex 5.

Annex 2: European Annex

1. Processing of Personal Data

1.1. Where Provider receives an instruction from Customer that, in Provider's reasonable opinion, infringes the GDPR, Provider will inform Customer.

1.2. Customer acknowledges and agrees that any instruction it issues regarding the Processing of Personal Data by or on behalf of Provider under or in connection with the Agreement will be in strict compliance with the GDPR and all other applicable laws.

2. Data protection impact assessment and prior consultation

2.1. Provider, taking into account the nature of the Processing and the information available to it, will provide reasonable assistance to Customer, at Customer's cost, on Customer's written request, to the extent reasonably necessary and technically feasible, with any data protection impact assessment and prior consultation with Supervisory Authorities as may be required of Customer under Article 35 or Article 36 of the GDPR, in each case solely in relation to Provider's Processing of Personal Data.

2.2. Except to the extent prohibited by applicable law, Customer is fully responsible for all time spent by Provider, at Provider's then-current professional services rates, in providing cooperation and assistance under paragraph 2.1, and will on demand reimburse Provider for those costs.

3. Restricted Transfers

EU Restricted Transfers

3.1. To the extent that any Processing of Personal Data under this DPA involves an EU Restricted Transfer from Customer to Provider, the parties will comply with their respective obligations set out in the SCCs, which are deemed to be (a) populated in accordance with Part 1 of Attachment 1 to this Annex 2; and (b) entered into by the parties and incorporated by reference into this DPA.

UK Restricted Transfers

3.2. To the extent that any Processing of Personal Data under this DPA involves a UK Restricted Transfer from Customer to Provider, the parties will comply with their respective obligations set out in the SCCs as varied by the UK Transfer Addendum, which are deemed to be (a) varied to address the requirements of the UK GDPR in accordance with the UK Transfer Addendum and populated in accordance with Part 2 of Attachment 1 to this Annex 2; and (b) entered into by the parties and incorporated by reference into this DPA.

Swiss Restricted Transfers

3.3. To the extent that any Processing of Personal Data under this DPA involves a Swiss Restricted Transfer from Customer to Provider, the parties will comply with their respective obligations set out in the SCCs, which are deemed to be (a) varied to address the requirements of the FADP and populated in accordance with Part 3 of Attachment 1 to this Annex 2; and (b) entered into by the parties and incorporated by reference into this DPA. Nothing in any applicable SCCs, as deemed amended by this paragraph 3.3, should be interpreted or construed in a way that would limit or exclude the rights of Data Subjects under Clause 18(c) of those SCCs to bring legal proceedings before the courts in Switzerland where Switzerland is that Data Subject's place of habitual residence.

Note on New Zealand adequacy

3.4. New Zealand benefits from an adequacy decision of the European Commission and from a UK adequacy regulation. Accordingly, a transfer of Personal Data from the EEA or the UK to Provider in New Zealand is not, of itself, a Restricted Transfer. The SCCs apply to onward transfers to any Subprocessor located in a country that does not benefit from an adequacy decision, and to any Processing by Provider outside New Zealand, as set out on the Subprocessor Site.

Adoption of a new transfer mechanism

3.5. Provider may, on notice, vary this DPA and replace the relevant SCCs with (a) any new form of the relevant SCCs, or any replacement for them, prepared and populated to the extent necessary to maintain compliance with Applicable Data Protection Laws, provided the replacement does not materially decrease the overall protection of Personal Data under the SCCs; or (b) another valid transfer mechanism, other than the SCCs, that Provider reasonably determines is necessary to maintain compliance with Chapter V of the GDPR for the relevant transfer and that does not materially diminish the data protection safeguards for Personal Data under this DPA.

Provision of full-form SCCs

3.6. In respect of any given Restricted Transfer, if a Supervisory Authority, Data Subject or further Controller requests it of Customer, then on specific written request made to the contact details in Annex 1 and accompanied by suitable supporting evidence of the request, and to the extent required to evidence Customer's compliance with Applicable Data Protection Laws, Provider will provide Customer within a reasonable time with an executed version of the relevant SCCs, amended and populated in accordance with Attachment 1 to this Annex 2, for countersignature by Customer, onward provision to the requestor, or storage.

Operational clarifications

3.7. When complying with its transparency obligations under Clause 8.3 of the SCCs, Customer agrees that it will not provide or otherwise make available, and will take all appropriate steps to protect, Provider's and its licensors' trade secrets, business secrets, confidential information and other commercially sensitive information.

3.8. Where applicable, for the purposes of Clause 10(a) of Module Three of the SCCs, Customer acknowledges and agrees that there are no circumstances in which it would be appropriate for Provider to notify any third-party controller of any Data Subject Request, and that any such notification is the sole responsibility of Customer.

3.9. For the purposes of Clause 15.1(a) of the SCCs, except to the extent prohibited by applicable law or by the relevant public authority, as between the parties Customer is solely responsible for making any notification to relevant Data Subjects if and as required.

3.10. Section 8 of this DPA applies in relation to Provider's appointment and use of Subprocessors under the SCCs. Any approval by Customer of Provider's appointment of a Subprocessor that is given expressly or deemed given under section 8 constitutes Customer's documented instructions to effect disclosures and onward transfers of Personal Data to that Subprocessor solely in connection with the Services, if and as required under Clause 8.8 of the SCCs.

3.11. The audits described in Clauses 8.9(c) and 8.9(d) of the SCCs are subject to section 9 of this DPA.

3.12. Certification of deletion of Personal Data as described in Clauses 8.5 and 16(d) of the SCCs will be provided only on Customer's written request.

Attachment 1 to Annex 2: Population of the SCCs

In the context of any EU Restricted Transfer, the SCCs populated in accordance with Part 1 below are incorporated by reference into and form an effective part of this DPA, if and where applicable in accordance with paragraph 3.1 of Annex 2.

In the context of any UK Restricted Transfer, the SCCs as varied by the UK Transfer Addendum and populated in accordance with Part 2 below are incorporated by reference into and form an effective part of this DPA, if and where applicable in accordance with paragraph 3.2 of Annex 2.

In the context of any Swiss Restricted Transfer, the SCCs as varied and populated by Part 3 below are incorporated by reference into and form an effective part of this DPA, if and where applicable in accordance with paragraph 3.3 of Annex 2.

Part 1: Population of the SCCs

1. Signature. Where the SCCs apply in accordance with paragraph 3.1 of Annex 2, each party is deemed to have signed the SCCs at the relevant signature block in Annex I to the Appendix to the SCCs.

2. Modules. The following modules of the SCCs apply, having regard to the roles of Customer under the Agreement and as set out in Annex 1:

  • Module Two applies to any EU Restricted Transfer or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Customer is a Controller in its own right; and
  • Module Three applies to any EU Restricted Transfer, UK Restricted Transfer or Swiss Restricted Transfer involving Processing of Personal Data in respect of which Customer is itself acting as a Processor on behalf of any other person.

3. Population of the body of the SCCs. For each Module, the following applies as and where applicable to that Module and its Clauses:

  • The optional "Docking Clause" in Clause 7 is not used, and the body of that Clause 7 is left intentionally blank.
  • In Clause 9, OPTION 2 (GENERAL WRITTEN AUTHORISATION) applies, and the minimum time period for advance notice of the addition or replacement of Subprocessors is the notice period set out in section 8(d) of this DPA, currently fifteen (15) days. OPTION 1 (SPECIFIC PRIOR AUTHORISATION) is not used and that optional language is deleted, as is Annex III to the Appendix to the SCCs.
  • In Clause 11, the optional language is not used and is deleted.
  • In Clause 13, all square brackets are removed and all text in them is retained.
  • In Clause 17, OPTION 1 applies, and the parties agree that the SCCs are governed by the law of Ireland in relation to any EU Restricted Transfer. OPTION 2 is not used and that optional language is deleted.
  • For the purposes of Clause 18, the parties agree that any dispute arising from the SCCs in relation to any EU Restricted Transfer will be resolved by the courts of Ireland, and Clause 18(b) is populated accordingly.

4. Population of the Annexes to the Appendix to the SCCs.

4.1. Annex I to the Appendix to the SCCs is populated with the corresponding information detailed in Annex 1 to this DPA, with Customer being the "data exporter" and Provider being the "data importer".

4.2. Part C of Annex I to the Appendix to the SCCs is populated as follows. The competent supervisory authority is determined as follows. Where Customer is established in an EU Member State, the competent supervisory authority is the supervisory authority of that Member State. Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies and Customer has appointed an EU representative under Article 27 of the GDPR, the competent supervisory authority is the supervisory authority of the Member State in which that representative is based from time to time. Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies, but Customer has not appointed an EU representative, the competent supervisory authority is the supervisory authority of the EU Member State notified in writing to Provider's contact point for data protection identified in Annex 1, which must be a Member State in which the Data Subjects whose Personal Data is transferred under the SCCs in relation to the offering of goods or services to them, or whose behaviour is monitored, are located.

4.3. Annex II to the Appendix to the SCCs is populated as follows. Refer to section 4 of this DPA and Annex 4 (Security Measures). If Customer receives a Data Subject Request under the EU GDPR and requires assistance from Provider, Customer should email Provider's contact point for data protection identified in Annex 1. When Provider engages a Subprocessor under the SCCs, Provider will enter into a binding contractual arrangement with that Subprocessor that, to the extent applicable to the nature of the services provided, imposes data protection obligations which in substance meet or exceed the relevant standards required under the SCCs and this DPA, including in respect of appropriate technical and organisational information security measures, notification of Information Security Incidents to Provider, return or deletion of Personal Data as and where required, and the engagement of further Subprocessors.

Part 2: UK Restricted Transfers

1.1. Where relevant in accordance with paragraph 3.2 of Annex 2, the SCCs also apply in the context of UK Restricted Transfers as varied by the UK Transfer Addendum, in the manner described below.

  • Part 1 of the UK Transfer Addendum. As permitted by Section 17 of the UK Transfer Addendum, the parties agree that Tables 1, 2 and 3 to the UK Transfer Addendum are deemed populated with the corresponding details set out in Annex 1 and in this Attachment 1, subject to the variations effected by the Mandatory Clauses; and Table 4 to the UK Transfer Addendum is completed by the box labelled "Data Importer" being deemed to have been ticked.
  • Part 2 of the UK Transfer Addendum. The parties agree to be bound by the Mandatory Clauses of the UK Transfer Addendum.

1.2. In relation to any UK Restricted Transfer to which they apply, where the context permits and requires, any reference in this DPA to the SCCs is read as a reference to those SCCs as varied in the manner set out in this Part 2.

Part 3: Swiss Restricted Transfers

1.1. Where applicable in accordance with paragraph 3.3 of Annex 2, the SCCs also apply in the context of Swiss Restricted Transfers with the following terms deemed to have the following substituted meanings: "GDPR" means the FADP; "European Union", "Union" and "Member State" each mean Switzerland; and "supervisory authority" means the FDPIC.

1.2. In relation to any Swiss Restricted Transfer to which they apply, where the context permits and requires, any reference in this DPA to the SCCs is read as a reference to those SCCs as varied in the manner set out in this Part 3.

Annex 3: State Privacy Laws Annex

For the purposes of this Annex 3, the terms "business", "controller", "processor", "commercial purpose", "sell", "share", "service provider" and "contractor" have the respective meanings given to them in the applicable State Privacy Laws, and "personal information" means Personal Data to the extent it constitutes "personal information" or "personal data", or a similar term, governed by the State Privacy Laws.

It is the parties' intent that, with respect to any personal information, Provider is a service provider, contractor or processor, as applicable under the State Privacy Laws. Provider (a) acknowledges that personal information is disclosed by Customer only for the limited and specified purposes described in the Agreement; (b) will comply with applicable obligations under the State Privacy Laws and will provide the same level of privacy protection to personal information as is required by the State Privacy Laws; (c) agrees that Customer has the right to take reasonable and appropriate steps to help ensure that Provider's Processing of personal information is consistent with Customer's obligations under the State Privacy Laws; (d) will notify Customer in writing of any determination made by Provider that it can no longer meet its obligations under the State Privacy Laws; and (e) agrees that Customer has the right, on reasonable notice, to take reasonable and appropriate steps to stop and remediate unauthorised use of personal information.

Provider will not (a) sell or share any personal information; (b) retain, use or disclose any personal information for any purpose other than the specific purpose of providing the Services, including retaining, using, or disclosing the personal information for a commercial purpose other than the provision of the Services, or as otherwise permitted by the State Privacy Laws; (c) retain, use or disclose the personal information outside of the direct business relationship between Provider and Customer; or (d) combine personal information received under the Agreement with personal information received from or on behalf of another person, or collected from Provider's own interaction with any Data Subject to whom that personal information pertains, except as and to the extent permitted by the State Privacy Laws and necessary as part of Provider's provision of the Services. Provider certifies that it understands its obligations under this paragraph and will comply with them.

Giving Customer notice of Subprocessor engagements in accordance with section 8 of this DPA satisfies Provider's obligation under the State Privacy Laws to give notice of, and an opportunity to object to, those engagements.

Customer may conduct audits, in accordance with section 9 of this DPA, to help ensure that Provider's use of personal information is consistent with Provider's obligations under the State Privacy Laws.

The parties acknowledge that Provider's retention, use and disclosure of personal information authorised by Customer's instructions documented in the Agreement and this DPA are integral to Provider's provision of the Services and to the business relationship between the parties.

Annex 4: Security Measures

Provider maintains the following measures. Further detail is published on our Security and Trust page.

  • Organisational management and personnel with assigned responsibility for the development, implementation and maintenance of Provider's information security programme.
  • Audit and risk assessment procedures for the periodic review and assessment of risks to Provider's organisation, for monitoring and maintaining compliance with Provider's policies and procedures, and for reporting the condition of its information security and compliance to internal senior management.
  • Data security controls which include, at a minimum, logical segregation of data, restricted role-based access and monitoring, and use of commercially available industry-standard encryption technologies, or materially equivalent safeguards, for Personal Data when transmitted over public networks or wirelessly, and at rest.
  • Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions, for example granting access on a need-to-know and least-privilege basis, use of unique user IDs and appropriate authentication credentials for all users, and periodic review and prompt revocation or change of access when employment terminates or job functions change.
  • Password controls designed to manage and control password strength, expiry and usage, including prohibiting users from sharing passwords, and password controls for Provider's employees consistent with generally accepted industry standards and appropriate to the risk, including minimum password length and use of multi-factor authentication as appropriate; credentials not being stored in readable format on Provider's computer systems, for example being stored using industry-standard hashing and salting; appropriate complexity or other compensating controls; a history threshold to prevent reuse of recent passwords; and newly issued or reset passwords being changed after first use.
  • System audit or event logging and related monitoring procedures to proactively record user access and system activity.
  • Physical and environmental security of data centres, server room facilities and other areas containing Personal Data, designed to protect information assets from unauthorised physical access, to manage, monitor and log movement of persons into and out of facilities as appropriate, and to guard against environmental hazards such as heat, fire and water damage. Provider relies on the physical security controls of its cloud infrastructure provider, as described in Annex 5 and on the Security and Trust page.
  • Operational procedures and controls to provide for the secure configuration, monitoring and maintenance of technology and information systems, including secure disposal of systems and media in accordance with commercially reasonable industry standards to render all information contained in them unreadable and, to the extent technically feasible, unrecoverable before final disposal or release from Provider's possession.
  • Change management procedures and tracking mechanisms designed to test, approve and monitor all material changes to Provider's technology and information assets that may affect the security of Personal Data.
  • Incident management procedures designed to allow Provider to investigate, respond to, mitigate, and provide notifications in accordance with this DPA regarding events related to Provider's technology and information assets.
  • Network security controls designed to protect systems from intrusion and limit the scope of any successful attack, including the use of firewalls and network segmentation, and intrusion detection or prevention, monitoring, and traffic and event correlation procedures.
  • Vulnerability assessment, patch management and threat protection technologies, and scheduled monitoring procedures designed to identify, assess, mitigate and protect against identified security threats, viruses and other malicious code.
  • Business resilience, continuity and disaster recovery procedures designed to maintain service and to recover from foreseeable emergencies or disasters.

Annex 5: List of Subprocessors

Customer approves Provider's engagement of the Subprocessors listed at www.paidnice.com/sub-processors, which forms part of this DPA and is updated in accordance with section 8(d).

Annex 6: New Zealand and Australia Annex

1. New Zealand

1.1. Agent status. The parties record that, in respect of Personal Data Processed on Customer's behalf, Provider holds that information solely as an agent for Customer for the purposes of section 11 of the NZ Privacy Act. Customer remains the agency that holds the information.

1.2. Instructions and purpose. Provider will use and disclose that Personal Data only as necessary to provide the Services and on Customer's instructions, consistent with information privacy principles 10 and 11.

1.3. Indirect collection (IPP3A). Where Provider collects Personal Data about individuals from a source other than the individual, including debtor contact details received through Customer's connected accounting platform, Customer is responsible for taking the steps required by information privacy principle 3A to make those individuals aware of the collection, for example through Customer's own privacy notice. Provider's Privacy Policy also serves as notice of that collection.

1.4. Cross-border disclosure (IPP12). Customer authorises Provider to disclose Personal Data to Subprocessors located outside New Zealand as listed on the Subprocessor Site. Provider will only make such a disclosure where at least one of the grounds in information privacy principle 12 is satisfied, which will ordinarily be that the Subprocessor is required to protect the information in a way that, overall, provides comparable safeguards to those in the NZ Privacy Act, secured through binding contractual terms consistent with section 8(c) of this DPA. Where Provider relies on model contract clauses or on the recipient being subject to prescribed comparable privacy laws, Provider will maintain records of that basis and make them available to Customer on reasonable request.

1.5. Notifiable privacy breach. Provider will notify Customer of any Information Security Incident in accordance with section 4(c), so that Customer can assess whether it is a notifiable privacy breach under Part 6 of the NZ Privacy Act. As the agency that holds the information, Customer is responsible for notifying the OPC and affected individuals. Provider will provide reasonable assistance with that assessment and notification.

1.6. Access and correction. Provider will provide the assistance described in section 6 to enable Customer to respond to requests made under information privacy principles 6 and 7 within the 20 working day period set by the NZ Privacy Act.

2. Australia

2.1. Application. This paragraph 2 applies where Customer is an APP entity, or where the Australian Privacy Act otherwise applies to the Processing.

2.2. Australian Privacy Principles. Provider will handle Personal Data in a manner that, if Provider were an APP entity, would not breach the Australian Privacy Principles, and in particular APP 6 (use and disclosure) and APP 11 (security of personal information).

2.3. Cross-border disclosure (APP 8). Customer authorises Provider to disclose Personal Data to Subprocessors located outside Australia as listed on the Subprocessor Site. Provider will take such steps as are reasonable in the circumstances to ensure that each overseas recipient does not breach the Australian Privacy Principles in relation to that Personal Data, through binding contractual terms consistent with section 8(c) of this DPA.

2.4. Notifiable Data Breaches. Provider will notify Customer of any Information Security Incident in accordance with section 4(c), so that Customer can assess whether it is an eligible data breach under Part IIIC of the Australian Privacy Act. Customer is responsible for notifying the OAIC and affected individuals. Provider will provide reasonable assistance with that assessment and notification.

2.5. Direct marketing and unsolicited messages. Customer is responsible for compliance with APP 7 and with the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth) in respect of any communication the Services send to Customer's own customers, as set out in section 7(b) of this DPA and section 6A of the Agreement.

Contact

Questions about this DPA, requests for a countersigned copy, and Subprocessor objections should be sent to the Privacy Officer, Paidnice Limited, Suite 14537, 17B Farnham Street, Parnell, Auckland 1052, New Zealand, or by email to [email protected].