Skip to Content
Data & PrivacyData Processing Addendum (DPA)

Data Processing Addendum (DPA)

Version 1.1 · Effective from 1 September 2026 · Last reviewed 27 August 2026

Download PDF

Parties. This Data Processing Addendum pursuant to Article 28 GDPR  (the “DPA”) is between the customer identified in the Terms of Service (the “Controller”) and CashXChain UG (haftungsbeschränkt), Georg-Bichler-Str. 9, 83620 Feldkirchen-Westerham, Germany (the “Processor”). It does not stand alone: it forms an integral part of the Terms of Service under clause 3.1 of that document, and applies where the Processor processes personal data on behalf of the Controller.

1. Definitions

Terms such as “personal data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject” and “personal data breach” have the meanings given in the GDPR .

2. Subject matter and duration

The subject matter, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1. Processing continues for the term of the Terms of Service.

3. Instructions

The Processor processes personal data only on the Controller’s documented instructions, including as to international transfers, unless required otherwise by law, in which case it informs the Controller unless the law prohibits this. The Processor informs the Controller if it considers an instruction infringes data protection law.

4. Confidentiality

The Processor ensures that persons authorised to process the personal data are bound by an obligation of confidentiality.

5. Security

The Processor implements the technical and organisational measures required by Article 32 GDPR , as described in Annex 2 (our Security Statement).

6. Sub-processors

The Controller gives general authorisation for the Processor to engage the sub-processors listed in our Sub-processor List (Annex 3). The Processor informs the Controller of intended changes and gives the Controller the opportunity to object. The Processor imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains liable for its sub-processors.

7. Data subject rights

Taking account of the nature of the processing, the Processor assists the Controller by appropriate measures to respond to requests to exercise data subject rights.

8. Assistance

The Processor assists the Controller in ensuring compliance with its obligations under Articles 32 to 36 GDPR  (security, breach notification, data protection impact assessments and prior consultation), taking into account the information available to the Processor.

9. Personal data breach

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s personal data, with the information the Controller reasonably needs to meet its own obligations.

10. Deletion or return

On termination of the services, the Processor deletes or returns all personal data at the Controller’s choice, and deletes existing copies, unless the law requires storage.

11. Audits

The Processor makes available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR  and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality and security conditions.

12. International transfers

Where processing involves a transfer of personal data outside the EEA to a country without an adequacy decision, the transfer is made under the European Commission’s Standard Contractual Clauses together with any further measures required.

13. Liability

Liability under this DPA is governed by Article 82 GDPR  and the liability provisions of the Terms of Service.

14. Governing law, jurisdiction and arbitration

Governing law and forum are set out in the Contracting Entity & Governing Law page and are not restated here. In summary: Swiss substantive law applies, the Commercial Court of the Canton of Zurich  has jurisdiction for customers in the EU, EEA or EFTA, and arbitration under the Swiss Rules with seat in Zurich applies elsewhere.

Annex 1 — Details of the processing. Subject matter: provision of the CashXChain platform. Nature and purpose: hosting, transmitting and processing transaction and account data to deliver the service. Types of personal data: business representative and authorised-user identifiers, contact details, transaction data, and payee data. Categories of data subjects: the Controller’s authorised users and the payees it pays. Duration: the term of the Terms of Service.

Annex 2 — Technical and organisational measures. As set out in our Security Statement, as updated from time to time.

Annex 3 — Sub-processors. As set out in our Sub-processor List, as updated from time to time.