Legal Center
Xonbay legal document

Xonbay Data Processing Agreement

Contractual terms for personal data Xonbay processes on behalf of eligible business customers.

Version 1.0
Effective 1 August 2026
Updated 15 July 2026
Section 1

Parties, scope and incorporation

This Data Processing Agreement forms part of the agreement between the business customer identified in the applicable service order or account and the Xonbay contracting entity identified in the main agreement.

Not automatically suitable for every merchant

Confirm when Xonbay is acting as processor rather than independent controller. Marketplace account, security, fraud and regulatory processing may remain controller activities governed by the Privacy Policy.

Section 2

Definitions

Controller
The party determining the purposes and means of processing personal data.
Processor
The party processing personal data on behalf of a controller.
Customer Data
Personal data submitted to the services by or for the business customer and processed by Xonbay on documented instructions.
Subprocessor
A third party engaged by Xonbay to process Customer Data on behalf of the customer.
Applicable Data Protection Law
Data-protection and privacy law applicable to the processing, including Ghana’s Data Protection Act 2012 and, where applicable, the GDPR or other relevant law.
Section 3

Details of processing

ItemDescription
Subject matterHosting and operating Xonbay business, storefront, order, customer-support and related services
DurationFor the term of the services plus limited retention and deletion periods described in the agreement
Nature and purposeStorage, organisation, retrieval, transmission, support, security, backup and other processing needed to provide the services
Data subjectsBuyers, prospective buyers, merchant staff, authorised users, contacts and other individuals whose data the customer submits
Personal-data typesNames, contact details, addresses, order details, communications, customer references and other data configured by the customer
Special-category dataNot intended for submission unless expressly supported and agreed in writing
Section 4

Documented instructions

Xonbay will process Customer Data only on documented instructions from the customer, including instructions contained in the main agreement and ordinary use of configured service features, unless processing is required by applicable law.

Section 5

Confidentiality and personnel

Xonbay will ensure that personnel authorised to process Customer Data are subject to appropriate confidentiality obligations and receive access only as needed for their responsibilities.

Section 6

Security measures

  1. Access controls and least-privilege practices.
  2. Encryption in transit and appropriate encryption at rest.
  3. Secure software-development and change-management practices.
  4. Logging, monitoring and incident-response processes.
  5. Backup, recovery and service-continuity controls.
  6. Vendor and subprocessor risk management.
  7. Periodic review of technical and organisational measures.

Attach actual measures

Replace this summary with a maintained security schedule describing Xonbay’s real architecture, authentication, encryption, backup, logging, vulnerability management and incident processes.

Section 7

Subprocessors

The customer authorises Xonbay to use subprocessors subject to appropriate contractual protections. Xonbay should maintain a current subprocessor list and provide a reasonable mechanism for customers to receive notice of material additions.

SubprocessorServiceProcessing locationPurpose
[Cloud host]Infrastructure[Country/region]Application hosting, storage and backups
[Email provider]Communications[Country/region]Transactional email
[Monitoring provider]Reliability[Country/region]Error monitoring and operational logs
[Support provider]Customer support[Country/region]Support-ticket processing
Section 8

Data-subject requests

Taking account of the nature of processing, Xonbay will provide reasonable assistance through appropriate technical and organisational measures to help the customer respond to valid data-subject requests.

Section 9

Personal-data incidents

Xonbay will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Data and will provide available information reasonably required for the customer’s assessment and notifications.

Set an operational notification process

Define the security contact, notification channel, internal escalation, evidence preservation and target notification timing in Xonbay’s incident-response plan.

Section 10

Compliance assistance and audits

Xonbay will make available information reasonably necessary to demonstrate compliance with applicable processor obligations and will support proportionate audits subject to confidentiality, security, scope, frequency and cost safeguards.

Section 11

International transfers

Where Customer Data is transferred internationally, the parties will use a legally recognised transfer mechanism and supplementary safeguards where required. If GDPR applies, this may include adequacy decisions or applicable Standard Contractual Clauses.

Section 12

Return and deletion

At the end of the services, Xonbay will delete or return Customer Data in accordance with the customer’s available export options, documented instructions and Xonbay’s deletion schedule, unless applicable law requires continued retention.

Section 13

Order of precedence

If this DPA conflicts with the main service agreement regarding processor obligations, this DPA controls to the extent of that conflict. Mandatory data-protection law controls over both.

Section 14

Data-protection contact

DPA and security enquiries

privacy@xonbay.com

[Insert registered business address], Ghana

Contact form