1. Parties, scope and precedence
MandateShield contracting processorGökhan VodinaliGäbelbachstrasse 39, 3027 BernSwitzerland (CH)Legal form / registration: Individual operator; no commercial-register number providedsupport@hemelion.comThis DPA is between that provider and the Customer identified in the clickwrap or order. It applies only where MandateShield processes Customer Personal Data as processor, service provider or contractor on Customer's behalf. Customer is controller or business. If this DPA conflicts with the Terms on that processing, this DPA controls.
2. Instructions and compliance
Customer instructs MandateShield to process Customer Personal Data only to provide, secure, meter and maintain the documented service; follow lawful configuration and API requests; prevent abuse; and delete or return data as provided here. MandateShield will notify Customer if an instruction appears to violate applicable data law, unless prohibited. Customer is responsible for lawful instructions, notices, rights, accuracy, minimization and legal bases.
3. Confidentiality and security
Persons authorized to process Customer Personal Data are bound by confidentiality. MandateShield maintains measures appropriate to the documented service and risk, including TLS transport, hashed API secrets, role-scoped credentials, authenticated encryption for optional provider credentials, tenant scoping, bounded input, replay and idempotency controls, retention cleanup, export, revocation and deletion controls, signed evidence and recovery procedures. These measures do not constitute an ISO, SOC or penetration-test certification.
4. Subprocessors
Customer gives general authorization for subprocessors listed at /subprocessors. MandateShield will impose materially equivalent data-protection duties and remains responsible to Customer for their processing to the extent required by law. Where practicable, the list will be updated before materially different processing begins. Customer may object on reasonable data-protection grounds; if no practical resolution exists, Customer may discontinue the affected service.
5. Security incidents
MandateShield will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and provide information reasonably available for Customer's obligations. Notice is not an admission of fault. Customer is responsible for maintaining a current contact and for notifications for which it is controller.
6. Assistance, rights and assessments
Taking account of the nature of processing and information available, MandateShield will reasonably assist with data-subject requests, breach duties, security assessments, impact assessments and prior consultations. If a request concerns data controlled by Customer, MandateShield may direct the requester to Customer and will not independently respond except as authorized or legally required.
7. Return, deletion and legally retained records
On account deletion or termination, active Customer Personal Data is deleted or made available through self-service export according to the documented controls, except for unresolved execution or billing state, mandatory records, minimal contract/security/claims evidence and isolated backups that expire under their cycle. MandateShield will not use retained data for ordinary service delivery.
8. Audit information
MandateShield will make information reasonably necessary to demonstrate these obligations available through documentation, control evidence, export and security materials. No more than once annually, unless a material incident or regulator requires otherwise, Customer may request a bounded audit by an independent qualified auditor under confidentiality, without accessing other customers' data or creating security risk. Customer bears reasonable costs not caused by a verified material breach.
9. International transfers
Each party will use a lawful transfer mechanism required for its processing. Where the EU Standard Contractual Clauses are validly incorporated, the controller-to-processor module applies with Customer as exporter and MandateShield as importer, supplemented by required Swiss adaptations or a UK Addendum where applicable. This clause does not claim that an instrument has been executed where it has not.
10. US service-provider terms
MandateShield will not sell or share Customer Personal Data; retain, use or disclose it outside the limited business purposes in the agreement; or combine it with personal data from another source except as permitted by applicable law. MandateShield will notify Customer if it determines it can no longer meet these duties and will permit reasonable steps to stop and remediate unauthorized use.
Schedule 1 — Processing details
- Subject and duration: hosted authority-policy, verification, lifecycle and evidence services for the agreement term plus documented deletion/return and lawful retention.
- Data subjects: Customer personnel, authorized users, agents, merchants/counterparties and end users only where Customer includes their bounded identifiers.
- Data: account identifiers, public keys and transaction, mandate, authority, execution and evidence metadata. Payment credentials and prohibited sensitive data are neither intended nor permitted.
- Frequency and purpose: as initiated by Customer, to provide, secure, meter and maintain the service.