Legal review required
Parties, scope and incorporation
This Data Processing Agreement forms part of the agreement between the business customer identified in the applicable service order or account and the Xonbay contracting entity identified in the main agreement.
Not automatically suitable for every merchant
Confirm when Xonbay is acting as processor rather than independent controller. Marketplace account, security, fraud and regulatory processing may remain controller activities governed by the Privacy Policy.
Definitions
- Controller
- The party determining the purposes and means of processing personal data.
- Processor
- The party processing personal data on behalf of a controller.
- Customer Data
- Personal data submitted to the services by or for the business customer and processed by Xonbay on documented instructions.
- Subprocessor
- A third party engaged by Xonbay to process Customer Data on behalf of the customer.
- Applicable Data Protection Law
- Data-protection and privacy law applicable to the processing, including Ghana’s Data Protection Act 2012 and, where applicable, the GDPR or other relevant law.
Details of processing
| Item | Description |
|---|---|
| Subject matter | Hosting and operating Xonbay business, storefront, order, customer-support and related services |
| Duration | For the term of the services plus limited retention and deletion periods described in the agreement |
| Nature and purpose | Storage, organisation, retrieval, transmission, support, security, backup and other processing needed to provide the services |
| Data subjects | Buyers, prospective buyers, merchant staff, authorised users, contacts and other individuals whose data the customer submits |
| Personal-data types | Names, contact details, addresses, order details, communications, customer references and other data configured by the customer |
| Special-category data | Not intended for submission unless expressly supported and agreed in writing |
Documented instructions
Xonbay will process Customer Data only on documented instructions from the customer, including instructions contained in the main agreement and ordinary use of configured service features, unless processing is required by applicable law.
Confidentiality and personnel
Xonbay will ensure that personnel authorised to process Customer Data are subject to appropriate confidentiality obligations and receive access only as needed for their responsibilities.
Security measures
- Access controls and least-privilege practices.
- Encryption in transit and appropriate encryption at rest.
- Secure software-development and change-management practices.
- Logging, monitoring and incident-response processes.
- Backup, recovery and service-continuity controls.
- Vendor and subprocessor risk management.
- Periodic review of technical and organisational measures.
Attach actual measures
Replace this summary with a maintained security schedule describing Xonbay’s real architecture, authentication, encryption, backup, logging, vulnerability management and incident processes.
Subprocessors
The customer authorises Xonbay to use subprocessors subject to appropriate contractual protections. Xonbay should maintain a current subprocessor list and provide a reasonable mechanism for customers to receive notice of material additions.
| Subprocessor | Service | Processing location | Purpose |
|---|---|---|---|
| [Cloud host] | Infrastructure | [Country/region] | Application hosting, storage and backups |
| [Email provider] | Communications | [Country/region] | Transactional email |
| [Monitoring provider] | Reliability | [Country/region] | Error monitoring and operational logs |
| [Support provider] | Customer support | [Country/region] | Support-ticket processing |
Data-subject requests
Taking account of the nature of processing, Xonbay will provide reasonable assistance through appropriate technical and organisational measures to help the customer respond to valid data-subject requests.
Personal-data incidents
Xonbay will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Data and will provide available information reasonably required for the customer’s assessment and notifications.
Set an operational notification process
Define the security contact, notification channel, internal escalation, evidence preservation and target notification timing in Xonbay’s incident-response plan.
Compliance assistance and audits
Xonbay will make available information reasonably necessary to demonstrate compliance with applicable processor obligations and will support proportionate audits subject to confidentiality, security, scope, frequency and cost safeguards.
International transfers
Where Customer Data is transferred internationally, the parties will use a legally recognised transfer mechanism and supplementary safeguards where required. If GDPR applies, this may include adequacy decisions or applicable Standard Contractual Clauses.
Return and deletion
At the end of the services, Xonbay will delete or return Customer Data in accordance with the customer’s available export options, documented instructions and Xonbay’s deletion schedule, unless applicable law requires continued retention.
Order of precedence
If this DPA conflicts with the main service agreement regarding processor obligations, this DPA controls to the extent of that conflict. Mandatory data-protection law controls over both.
Data-protection contact
DPA and security enquiries
Related legal documents
Review other policies and agreements that may apply to your use of Xonbay.
Terms of Service
The rules governing buyers, sellers, visitors, storefronts, orders and use of Xonbay services.
Privacy Policy
How Xonbay collects, uses, shares, protects and retains personal information relating to buyers, sellers and visitors.
Cookie Policy
How Xonbay uses cookies, local storage, pixels and similar technologies across its marketplace and seller storefronts.