1. Scope and order of precedence
This addendum applies when GatewayChanger processes personal data on behalf of a customer organization ("you") in the course of providing the routing service. It forms part of the terms of service. Where this addendum and the terms conflict on data protection, this addendum wins.
"GDPR" means Regulation (EU) 2016/679 and, where applicable, the UK GDPR. Terms such as controller, processor, personal data, processing and data subject have the meanings given there.
2. Roles of the parties
You are the controller of the personal data your shops send us. GatewayChanger is your processor for that data and processes it only on your documented instructions, which are: to evaluate your routing rules, to issue decisions and grants, to keep the ledger and settlement summaries, to send the alerts and webhooks you configure, and to provide support.
Configuring your rules, using the API and the dashboard, and enabling the plugins constitute documented instructions. If we believe an instruction breaches data protection law, we will tell you and may pause that processing.
3. Details of the processing (Annex I)
Subject matter: routing payment orders between the shops of one organization and recording the outcomes.
Duration: the term of your subscription, plus the retention periods below.
Nature and purpose: evaluating rules, issuing signed routing decisions, storing transaction outcomes and consent evidence, producing settlement reports, alerting, and support.
Categories of data subjects: your customers who place orders in your seller shops; your own staff who use the dashboard.
Types of personal data: order amounts and currency, billing and shipping country, an optional hashed email address, card brand and last four digits, processor references, order references, consent text with its hash, the consent timestamp, IP address and user agent; for dashboard users, name, email, hashed password and activity records.
Special categories: none. You must not send us special-category data, and the API gives you no field in which to do so.
Never processed: primary account numbers, CVV or CVC values, expiry dates, cardholder names, or processor credentials.
4. Security measures (Annex II)
- Encryption in transit (TLS) for every interface; encryption at rest for database storage and backups.
- Architectural minimisation: no cardholder data can enter the system, and logs are redacted by design.
- Ed25519-signed routing grants, signed shop-to-shop requests, nonce and timestamp replay protection.
- Per-shop and per-environment API keys with rotation; strict separation of test and live data.
- Least-privilege administrative access, multi-factor authentication for staff, and an audit log of administrative actions.
- Backups with tested restores, and monitoring with alerting on availability and integrity.
To be confirmed Backup frequency, restore targets and the penetration-test cadence will be stated here with dates.
5. Sub-processors (Annex III)
You give general authorisation for the sub-processors listed below. We will give at least 30 days' notice before adding or replacing one, and you may object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate the affected part of the Service without penalty.
To be confirmed The list will name each provider, its role (hosting and infrastructure, transactional email, error monitoring), and its processing location. Every sub-processor is engaged under a written contract with obligations no less protective than this addendum.
6. Confidentiality and staff
Everyone we allow to process personal data is bound by confidentiality, is trained on their obligations, and has access only to what their role requires.
7. Assistance with data subject requests
The dashboard and API let you find, export and delete the records relating to one order or one customer yourself. Where that is not enough, we will assist you within a reasonable time, taking into account the nature of the processing. If a data subject contacts us directly, we will refer them to you and tell you about it.
8. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any event in time for you to meet your own 72-hour obligation. The notification will describe what happened, the categories and approximate number of records involved, the likely consequences and the measures taken.
9. Return and deletion
On termination, your data remains exportable for 90 days. After that we delete it, except where we must keep records to comply with law — for example financial records — in which case we keep only what is required, for only as long as required, and continue to protect it.
10. Audits and information
We will make available the information reasonably needed to demonstrate compliance with this addendum and will contribute to audits, on reasonable notice, once a year, subject to confidentiality and without access to other customers' data. Where available, documentation and third-party reports may be used to satisfy an audit request.
11. International transfers
To be confirmed The hosting region will be named here. Where personal data is transferred outside the EEA or the UK, the transfer will rely on an adequacy decision or on the standard contractual clauses, with a transfer impact assessment where required. The clauses will be incorporated by reference and completed with the annexes above.
12. Liability
The liability provisions of the terms of service apply to this addendum, except where data protection law provides otherwise. To be confirmed alongside the liability cap in the terms.
Questions about this draft go to [email protected]. See also the compliance page for the plain-language version of how the service is built.