DATA PROCESSING AGREEMENT

Version: 1.2 

Last updated: September, 2026

This Data Processing Agreement (“DPA”) forms part of and is incorporated into the Chargebase Terms and Conditions, including any applicable Chargebase Fee Schedule, if any (together, the “Agreement”), between SPENDBASE INC. (“Spendbase”, “Company”, “we”, “us”), and the Seller identified in the applicable Chargebase Fee Schedule (“Customer”) (each a “Party” and together the “Parties”). This DPA is effective as of the Effective Date of the Agreement and applies whenever Company processes Personal Data on Customer’s behalf in connection with the Chargebase Platform and the Provider Services made available through it (together, the “Service”).

Company provides the Chargebase Platform as an authorised reseller of chargeback-prevention and dispute-alert services (“Provider Services”) supplied by Verifi, Inc. (“Verifi”) and Ethoca Technologies Inc. and Mastercard Europe SA (“Ethoca”) (together, the “Providers”).

1. ROLES OF THE PARTIES AND SCOPE OF THE DPA

1.1  For the purposes of this DPA, Customer is the Data Controller and Company is the Data Processor in respect of Controller Personal Data (as defined in Section 3), save as set out in Section 1.4.

1.2  Where Customer itself acts as a Data Processor on behalf of its own Data Controller, Company acts as a Sub-processor, and Customer warrants that it is authorised to appoint Company on those terms and that this DPA satisfies any requirements imposed by that Data Controller.Customer will notify Company in writing before or promptly upon relying on this Section 1.2, identifying the relevant Data Controller and confirming that Customer’s engagement of Company as Sub-processor is within the scope of Customer’s documented instructions from, and authorisation by, that Data Controller. Section 9.1 applies on the basis of the role notified under this Section.

1.3  Company may separately process certain Personal Data as an independent Data Controller (for example, website analytics, billing, fraud prevention relating to Company’s own services, and account administration) under its own Privacy Notice; that processing is not governed by this DPA.

1.4 To enable the Provider Services, Company transmits CE Data to the Providers. Both Providers act as Company’s Sub-processor for CE Data processed on Customer’s instructions, and separately as an independent Data Controller for defined purposes — including network-wide fraud monitoring, product development, aggregated reporting, and compliance with legal requirements; such processing is not governed by this DPA. This dual role is confirmed by Ethoca’s own reseller agreement with Company and is applied to Verifi by analogy, on the basis that Verifi operates a comparable card-scheme dispute-alert network.

2. THE SERVICE

2.1  Company provides the Chargebase Platform, a monitoring and analytics interface that gives Customer access to one or more Provider Services,  including chargeback and dispute alerts and, where applicable, Rapid Dispute Resolution and Order Insight functionality,  for the purpose of alert monitoring and chargeback-performance analytics in respect of Customer’s own card-not-present transactions.

2.2  In providing the Service, Company may process Personal Data on Customer’s behalf, as described in Annex I.

2.3  The Provider Services and Provider Platform are owned and operated by the relevant Provider; all dispute resolution activity takes place on the Provider Platform. Company’s processing role under this DPA is limited to the Chargebase Platform’s monitoring and analytics functions and to transmitting CE Data necessary to obtain the Provider Services Customer has requested.

3. DEFINITIONS

“Applicable Data Protection Law” means the EU GDPR, the UK GDPR, and any other data protection law applicable to the Processing under this DPA.

“Controller Personal Data” means the Personal Data processed by Company on Customer’s behalf under the Agreement, comprising Authorized User Data and CE Data (each as defined below).

“Authorized User Data” means the account, login and contact data of Customer’s Authorized Users who access the Chargebase Platform.

“CE Data” or “Customer Experience Data” means the transaction-level data and related customer service information that Customer submits to use the Services, as further described in Annex I and in documentation provided by Company,  including data relating to Customer’s own customers and cardholders who are not Customer’s employees.

“Providers” means Verifi, Inc. and Ethoca Technologies Inc./Mastercard Europe SA, or such other third-party providers of chargeback-prevention or dispute-alert services as are specified in the applicable Chargebase Fee Schedule.

“Provider Platform” and “Provider Services” have the meanings given in the Chargebase Terms and Conditions.

“Restricted Transfer” has the meaning given in Section 9.

“Data Controller”, “Data Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing”, and “Sub-processor” have the meanings given to them in the EU GDPR.

4. PROCESSING OF PERSONAL DATA

4.1  Company will process Controller Personal Data only on Customer’s documented instructions (including as set out in the Agreement and this DPA, and including the instruction inherent in Customer’s use of a given Provider Service to transmit the relevant CE Data to that Provider), unless required otherwise by law — in which case Company will inform Customer before processing, to the extent legally permitted.

4.2  Company will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.

4.3  The subject matter, duration, nature, purpose, and categories of Controller Personal Data and Data Subjects are set out in Annex I.

4.4  Customer acknowledges that, once CE Data is transmitted to a Provider to obtain a Provider Service, further processing of that CE Data on the Provider Platform is carried out under the Provider’s own terms and, to the extent described in Section 1.4, may fall outside Company’s instructable control as Processor.

5. CUSTOMER RESPONSIBILITIES

5.1  As Data Controller, Customer confirms that it: (a) has, and will maintain, a valid legal basis under Applicable Data Protection Law for the CE Data and Authorized User Data it submits to the Service, including for any processing of its own customers’/cardholders’ data for chargeback-prevention purposes; (b) has provided Data Subjects with the required privacy information, including as to Company’s and, where applicable, Providers’ processing; (c) will not submit special category data or children’s data without Company’s prior written agreement; (d) is solely responsible for the accuracy, adequacy, and minimisation of the data it submits, including ensuring CE Data is limited to what is genuinely necessary for the Provider Service requested; and (e) remains solely responsible for its own compliance with PCI-DSS and other card-network requirements in respect of any payment card data included in CE Data.

6. COMPANY OBLIGATIONS

6.1  Company will: (a) process Controller Personal Data only for the purposes of providing the Service, including transmitting CE Data to a Provider solely to obtain the Provider Service Customer has requested; (b) ensure personnel with access to Controller Personal Data are bound by confidentiality obligations; (c) not sell or share Controller Personal Data, or use it for any purpose other than providing the Service; and (d) provide reasonable assistance to Customer in responding to Data Subject requests, security incidents, and, where applicable, data protection impact assessments.

7. SECURITY

7.1.  Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk of varying likelihood and severity for the rights of Data Subjects, Company shall in relation to the Controller Personal Data implement and maintain appropriate technical and organizational measures in relation to its Processing of Controller Personal Data so as to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the EU GDPR.

7.2.  To the extent required under the Agreement and this DPA, the Company shall implement security measures as set forth in Annex II of this DPA.

7.3.  The Customer may request evidence of the Company’s security posture at any time by contacting [email protected]. Company may satisfy such requests by providing a current SOC 2 Type II report, ISO/IEC 27001 certification, or a completed security questionnaire.

8. SUB-PROCESSORS

8.1. By entering into this DPA, the Customer as a Data Controller gives general authorisation to the Company to engage Sub-processors on the terms of this Section 8. The up-to-date list of already engaged sub-processors may be presented upon the Customer’s request and\or in Annex III of this DPA. The Company shall notify the Customer of the amendments into the respective subprocessor list by amending the “Last updated date” and, if possible, send an email to the Customer’s registered address no less than 14 days prior to the change taking effect.

8.2. With respect to each Sub-processor, Company shall (a)  carry out adequate due diligence to ensure that the Sub-processor is capable of providing the level of protection for the Controller Personal Data required by this DPA; (b) ensure that the arrangement between the Processor and the Sub-processor is governed by a written contract including terms that offer no less onerous level of protection for the Controller Personal Data as one set out in this DPA; and (c) if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between the Processor and the Sub-processor.

8.3. Notwithstanding any authorization by the Data Controller within the meaning of the preceding sections, Company shall remain fully liable to the Controller for the performance of the Sub-processor’s obligations.

8.4. The Customer may reasonably object to the engagement of the respective Sub-processor at any time by sending the respective letter to the email enshrined herein. The Company shall review objections within 30 (thirty) days and, if possible, change the Sub-processor. If the objection cannot be resolved, the Company should notify the Customer without undue delay. 

9.  CROSS-BORDER TRANSFERS 

9.1. RESTRICTED TRANSFER. The Parties agree that when the transfer of Controller Personal data from the Customer (as “data exporter”) to Company (as “data importer”) is a Restricted Transfer and Data Protection Laws require that appropriate safeguards are put in place, the transfer will be subject to the EU SCCs, which are deemed incorporated into and form a part of this DPA, as follows. Where Customer acts as Controller under Section 1.1, Module Two (Controller-to-Processor) applies as set out in Section 9.1(a). Where Customer acts as Processor under Section 1.2, Module Three (Processor-to-Processor) applies as set out in Section 9.1(b) instead, and Company acts as Customer’s Sub-processor for the purposes of the EU SCCs:

  1. In relation to transfers of Controller Personal Data protected by the EU GDPR, the EU SCCs will apply, completed as follows:
  • Module Two will apply;
  • in Clause 7, the optional docking clause should not apply;
  • in Clause 9, Option 2 will apply, and the time period for prior notice of Sub-processor changes will be as set out in Clause 8.4 of this DPA;
  • in Clause 11, the option will not apply;
  • in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Irish law;
  • in Clause 18(b), disputes will be resolved before the courts of Ireland;
  • Annex I of the EU SCCs is deemed completed with the information set out in Annex I to this DPA, and the competent supervisory authority will be determined in accordance with the EU GDPR and Clause 13 of the EU SCCs;
  • subject to Section 7 of this DPA, Annex II of the EU SCCs is deemed completed with the information set out in Annex II to this DPA;
  • subject to section 8 of this DPA, Annex III of the EU SCCs is deemed completed with the information set out in Annex III to this DPA; and
  • No Annex IV is currently attached to this DPA; none of the Parties have agreed additional supplementary measures to the EU SCCs beyond those already set out in Annexes I–III.
  1. In relation to transfers of Controller Personal Data protected by the EU GDPR where Customer acts as Processor under Section 1.2, the EU SCCs will apply on Module Three terms, completed as follows:
  • Module Three will apply;
  • in Clause 7, the optional docking clause will not apply;
  • in Clause 9, Option 2 will apply, and the time period for prior notice of Sub-processor changes will be as set out in Clause 8.4 of this DPA;
  • in Clause 11, the optional language will not apply;
  • in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Irish law;
  • in Clause 18(b), disputes will be resolved before the courts of Ireland;
  • Annex I of the EU SCCs is deemed completed with the information set out in Annex I to this DPA, save that the Parties’ roles are stated as Processor (Customer, as Sub-processor’s onward instructing party) and Sub-processor (Company);
  • subject to Section 7 of this DPA, Annex II of the EU SCCs is deemed completed with the information set out in Annex II to this DPA; and
  • subject to Section 8 of this DPA, Annex III of the EU SCCs is deemed completed with the information set out in Annex III to this DPA.
  1. In relation to transfers of Personal Data protected by UK Data Protection Laws, the EU SCCs: (i) apply as completed in accordance with Clauses 9.1 (a) or 9.1. (b) above as applicable; and (ii) are deemed amended as specified by the UK Addendum, which is deemed executed by the Parties and incorporated into and form an integral part of this DPA. In addition, Tables 1 to 3 in Part 1 of the UK Addendum are deemed completed respectively with the information set out in Sections 7, 8, and 15 of this DPA, as well as Annex I, Annex II, and Annex III of this DPA; Table 4 in Part 1 is deemed completed by selecting “neither party”. Any conflict between the terms of the EU SCCs and the UK Addendum will be resolved in accordance with Sections 10 and 11 of the UK Addendum.

9.2. US TRANSFER. Where the Customer is a Business under the CCPA or subject to equivalent US state privacy laws, the following terms apply in addition to the main DPA:

  • Company acts as Service Provider under the CCPA and certifies it understands and will comply with the applicable Service Provider restrictions.
  • Company will not sell, share, retain, use, or disclose Personal Information outside the direct business relationship or for any purpose other than those specified in Annex I.
  • Company will not combine Personal Information received from the Customer with Personal Information from other sources except as permitted by applicable law.
  • Company will assist the Customer in responding to verifiable consumer requests (access, deletion, correction, opt-out of sale/sharing, limit use of sensitive personal information) within CCPA-required timeframes.
  • The Customer hereby retains the right to take reasonable steps to ensure Company uses Personal Information consistently with the given obligations, and to notify Company if it believes it is no longer able to meet its CCPA obligations.
  • For Virginia CDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA, and equivalent laws: Company agrees to act as a Processor, process data only on the respective instructions, maintain appropriate security, assist with consumer rights requests, delete or return data on the Customer request, and provide information necessary for data protection assessments.

9.3  For CE Data transmitted to Ethoca, transfers rely primarily on the Mastercard Binding Corporate Rules and, where those cannot be relied upon, on EU Standard Contractual Clauses Module 4 with the UK Addendum. For CE Data transmitted to Verifi, transfers are understood, by analogy with the Visa group’s published transfer practice, to rely on Standard Contractual Clauses or approved binding corporate rules; the specific mechanism has not been confirmed by a Verifi-specific agreement. CE Data may also be transmitted onward to Participating Issuers and other network participants worldwide under the Providers’ own network rules, outside Company’s instruction.

10. PERSONAL DATA BREACH

10.1. Company shall notify the Customer within forty-eight (48) hours if it or Sub-processor becomes aware of any unauthorized or unlawful Processing of, loss of, damage to, or destruction or corruption of Controller Personal Data, providing the Customer with sufficient information to allow the Controller to meet any obligations to report to competent authorities or inform Data Subjects. Such information shall as a minimum: (a) describe the nature of the Personal Data Breach, the categories and numbers of Data Subjects concerned, and the categories and numbers of Personal Data records concerned; (b) communicate the name and contact details of the Data Processor’s data protection officer or another relevant contact from whom more information may be obtained; (c) describe the likely consequences of the Personal Data Breach; (d) describe the measures taken or proposed to be taken by the Data Processor to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

10.2. The Company will cooperate with the Customer and take such reasonable steps to assist in the investigation, mitigation, and remediation of each Personal Data Breach.

11. DATA SUBJECT RIGHTS

11.1. Company will assist the Customer in fulfilling requests from Data Subjects exercising their rights under Applicable Data Protection Law (including rights of access, rectification, erasure, restriction, portability, objection, and opt-out of sale under the CCPA), taking into account the nature of the processing and the information available to Company.

11.2. If a Data Subject contacts Company directly to exercise a right, Company will forward the request to the Customer within five (5) business days and will not respond to the Data Subject directly without prior authorisation.

12. SUPERVISORY AUTHORITY INVESTIGATION

12.1. Both Parties shall cooperate and assist the other Party in the event of any measures or investigations taken by the Supervisory Authority related to any activities conducted under this DPA, including promptly notifying the other Party of the threat and commencement of such measures. The Parties shall take all reasonable measures necessary to limit the potential damage incurred to either of the Parties due to such event.

13. AUDIT RIGHTS

13.1. Company shall make available to the Customer on request in a timely manner such information as is reasonably required by the Data Controller to demonstrate Data Processor’s compliance with its obligations under Applicable Data Protection Laws and this DPA.

13.2.  This shall be subject to the Customer giving the Company reasonable prior notice, but no later than 30 days in advance of such audit and/or inspection and ensuring that any auditor is subject to binding obligations of confidentiality and that such audit or inspection is undertaken so as to cause minimal disruption to Company’s business and in the narrowest applicable extent. 

13.3. Company cannot be obliged to give access to its documents and records for the purposes of such an audit or inspection: (a) to any individual unless he or she produces reasonable evidence of identity and authority; (b) outside normal business hours, unless the audit or inspection needs to be conducted on an emergency basis and the Data Controller has given notice to the Data Processor that this is the case before attendance outside those hours begins.

13.4.  The Company may satisfy audit requests by providing a current SOC 2 Type II report, ISO/IEC 27001 certification, or completion of a reasonable security questionnaire, where these cover the relevant processing activities.

14. RETENTION AND DELETION

14.1  On termination of the Agreement, or on Customer’s written request, Company will delete or return Controller Personal Data it holds within 30 days, except to the extent Company is required by law to retain it.

14.2  Customer acknowledges that CE Data held on the Provider Platform, or retained by a Provider under card-scheme network rules, is not deleted by Company’s action under Section 14.1 and is instead governed by the applicable Provider’s own retention terms.

15. TERM, LIABILITY & MISCELLANEOUS

15.1  This DPA takes effect on the effective date of the Agreement and terminates automatically when the Agreement ends.

15.2  Each Party’s liability under this DPA is subject to the limitations and exclusions set out in the Agreement, except where such a limitation is prohibited by law.

15.3  In the event of conflict, the order of precedence is: (1) mandatory Applicable Data Protection Law; (2) the EU SCCs, UK Addendum, or EU–US DPF, where applicable; (3) this DPA; (4) the Agreement.

15.4  This DPA is governed by the law stated in the Agreement. For data protection enquiries, contact [email protected].

ANNEX I — DETAILS OF PROCESSING

SUBJECT MATTERProvision of the Chargebase Platform: chargeback and dispute-alert monitoring, analytics on dispute outcomes, and administration of access to Provider Services, as set out in the Agreement.
ROLE OF THE CUSTOMERAs Controller (Section 1.1), unless Customer has notified Company under Section 1.2 that it acts as Processor, in which case Customer acts as Processor and Company as Sub-processor for the purposes of Section 9 and the EU SCCs.
DURATIONFor as long as Company processes Controller Personal Data under the Agreement.
NATURE OF PROCESSINGReceipt of CE Data submitted by Customer; transmission of CE Data to the relevant Provider to obtain the requested Provider Service; display and monitoring of resulting Alerts and dispute-outcome data on the Chargebase Platform dashboard; no independent alteration of CE Data by Company.
PURPOSEDelivering the Service (chargeback/dispute alert monitoring, performance analytics); account administration; billing; customer support.
CATEGORIES OF PERSONAL DATAAuthorized User Data (name, business email, job title, account credentials); CE Data  (transaction-level and dispute-related data such as cardholder name, card or account number — which may be full or partial, not limited to masked/tokenised data — transaction amount and date, order reference, billing contact details, and associated customer-service communications); Payment data (tokenised references only, no card data, in respect of Customer’s own billing).
CATEGORIES OF DATA SUBJECTSCustomer’s Authorized Users (employees or contractors who use the Chargebase Platform); and Customer’s own customers/cardholders whose transaction and dispute data forms part of the CE Data submitted by Customer.
SENSITIVE DATANone intended. Special category data and children’s data must not be submitted without the Company’s prior written agreement. Because CE Data may include full, unmasked card numbers, PCI-DSS applicability to Company itself — not only Customer — should be assessed.
RETENTIONAs set out in Company’s Privacy Notice, and in any event no longer than necessary for the purposes above or as required by law, save that CE Data held by a Provider on the Provider Platform follows the Provider’s own retention terms (see Section 11.2).

ANNEX II — SECURITY MEASURES

Company maintains a comprehensive written information security program designed to protect Controller Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. This program includes the following safeguards:

SECURITY DOMAINMEASURES
GOVERNANCE AND CERTIFICATIONCompany has implemented an information security management system conforming to ISO/IEC 27001:2022 and SOC 2 Type II
ENCRYPTION IN TRANSITTLS 1.2 or higher on all Service endpoints; HTTPS enforced; no unencrypted transmission of Personal Data.
ENCRYPTION AT RESTAES-256 encryption for sensitive data stored on AWS infrastructure.
ACCESS CONTROLRole-based access control; least-privilege principle; unique user IDs issued to all personnel; shared accounts prohibited; multi-factor authentication for all administrative and remote access; monthly access reviews; access revoked promptly upon termination or role change; Controller Personal Data logically separated from other customer data.
CARD-SCHEME COMPLIANCECompany’s handling of payment-card elements within CE Data is subject to PCI-DSS; Customer remains responsible for its own PCI-DSS compliance (Section 5.1(e)).
INFRASTRUCTUREHosted on AWS Frankfurt (eu-central-1). AWS holds ISO/IEC 27001, SOC 1, SOC 2, and PCI DSS certifications. Remote access to production systems requires a secure VPN with multi-factor authentication. Firewalls are maintained to protect all networks hosting Controller Personal Data. Anti-malware software is deployed and automatically updated. Systems are kept current with security patches in accordance with defined patch management SLAs.
VULNERABILITY MANAGEMENTRegular automated vulnerability scanning; annual penetration testing by independent third parties; defined patch management SLAs.
INCIDENT RESPONSEDocumented incident response plan; 48-hour Customer notification commitment.
PERSONNEL SECURITYBackground checks for personnel with access to Personal Data where legally permissible; mandatory annual security awareness training; confidentiality agreements; access limited to those with a legitimate business need-to-know.
DATA DELETIONWhen storage media is retired or repurposed, data is securely deleted in accordance with NIST SP 800-88 Rev.1 or successor standards, rendering data irrecoverable.
BUSINESS CONTINUITYAutomated backups; defined RTO and RPO; disaster recovery plan.
AUDIT LOGGINGComprehensive logging of access to Personal Data; anomaly detection and alerting; logs retained for 90 days minimum.

ANNEX III — LIST OF SUBPROCESSORS 

Last updated: September 14, 2026

SUB-PROCESSORPROCESSING ACTIVITYDATA LOCATIONTRANSFER MECHANISM
Amazon Web Services, Inc.Cloud hosting/storage /infrastructure only (Company’s own systems). Does not include AWS Bedrock (LLM inference) — see Section 9.Frankfurt, Germany (eu-central-1)EU adequacy / AWS SCCs as supplementary mechanism.
Ethoca Technologies Inc.Ethoca Alerts — receipt and processing of CE Data to deliver dispute-prevention alerts (Rapid Dispute Resolution / Order Insight); independent processing per Section 1.4Belgium (Mastercard Europe SA) / CanadaMastercard Binding Corporate Rules; EU SCC Module 4 + UK Addendum as fallback; Belgian DPA competent
Verifi, Inc. (Provider)Rapid Dispute Resolution / Order Insight — receipt and processing of CE Data to deliver dispute-prevention alerts; independent processing per Section 1.4USAStandard Contractual Clauses or approved binding corporate rules at Visa group level (per Visa’s Global Privacy Notice); not confirmed by a Verifi-specific agreement
HubSpot, Inc.CRM and account communications (business contact data only)USAEU–US DPF certified; SCCs as supplementary mechanism.
Slack Technologies, LLCInternal webhook alerts — dispute notifications, fraud warnings, service monitoringUSAEU–US DPF / SCCs as supplementary mechanism.
Google LLC (OAuth2 / Google Workspace)Authentication and identity — Google OAuth2 login, optional Google Workspace SSOUSAEU–US DPF certified, SCC as supplementary mechanism.
GitHub, Inc. (GitHub OAuth2)Authentication — GitHub OAuth2 loginUSASCCs 
Microsoft Azure MonitorObservability — infrastructure monitoring, alerting, diagnosticsEU region (West Europe / North Europe)EU–US DPF / SCCs as supplementary mechanism.
Juro LtdContract lifecycle management — storage and processing of commercial agreements (business contact data of signatories)United KingdomUK GDPR — UK adequacy decision applies; SCCs for onward EEA transfers
Cloudflare, Inc.Content delivery network (CDN), DDoS protection, WAF, DNS resolution — processes IP addresses and HTTP request metadata of end usersGlobal (including EU nodes); data processed at edge closest to userEU–US DPF certified; SCCs for non-adequate country transfers
Stripe, Inc.Payment and billing processing (account metadata only; no prompt content)USAEU–US DPF certified