Data Processing Agreement (DPA)
Last updated: July 22, 2026
This agreement (the "DPA") supplements the Terms of Use and the Terms of Sale for personal data processing operations carried out by Aventopay on behalf of the Merchant (the "Data Controller").
1. Definitions
Terms used in this agreement have the meaning given by the GDPR (Regulation EU 2016/679).
2. Subject of processing
Aventopay acts as a data processor within the meaning of the GDPR when it processes, on behalf of the Merchant, the personal data of end customers collected during payments (name, email, IP address, amount, timestamp).
3. Nature and purpose of processing
The processing operations are intended to:
- Create and execute payment sessions
- Fight against fraud (IP analysis, velocity, usage patterns)
- Produce reporting and audit trails
4. Categories of data subjects
- End customers of the Merchant making a payment
- Users of the merchant dashboard
5. Categories of data
- Identification data (name, first name, email)
- Connection data (IP, user-agent, timestamp)
- Financial data (amount, currency, transaction reference)
Card data is not processed by Aventopay. It is processed exclusively by the licensed payment institutions that execute payment operations.
6. Aventopay obligations
Aventopay commits to:
- Process data only on documented instruction from the Data Controller (via T&Cs and merchant account settings)
- Guarantee confidentiality through appropriate technical and organisational measures (TLS 1.3 encryption, multi-tenant isolation, access control)
- Authorise access to data only to strictly necessary persons, subject to a confidentiality obligation
- Notify the Merchant of any data breach within 48h of becoming aware of it
- Assist the Merchant in complying with their GDPR obligations (data subject rights, DPIA, notifications to CNIL/VDAI)
- Delete or return data at the end of the contract, in agreed terms
7. Further sub-processors
Aventopay uses further sub-processors (licensed payment institutions, hosting provider). The up-to-date list is published on /legal/subprocessors. Any modification is notified with reasonable notice, allowing the Merchant to object.
8. Transfers outside the EU
Some sub-processors are established in the United States. These transfers are covered by the Data Privacy Framework and/or Standard Contractual Clauses of the European Commission.
9. Duration
This agreement takes effect upon acceptance of the T&Cs and ends when the merchant account is closed. Data is retained according to the durations defined in the privacy policy.
10. Contact
Any question relating to this DPA: privacy@avento-pay.com.
Download PDF version (coming soon).
