GDPR Article 28 Data Processing Agreement for SatsRail merchants
This Data Processing Agreement ("DPA") forms part of the SatsRail Terms of Service and governs the processing of personal data by SatsRail on behalf of merchants who are subject to the European Union General Data Protection Regulation (GDPR) or the UK GDPR.
SatsRail processes the following categories of personal data on behalf of merchants:
| Data Category | Examples | Purpose |
|---|---|---|
| Merchant account data | Email address, business name, phone number | Account management, service delivery |
| Transaction data | Lightning invoices, payment amounts, payment status, order records | Payment processing, reporting |
| Technical data | IP addresses, API usage logs, device information | Security, service operation |
SatsRail does not process:
SatsRail shall:
SatsRail currently uses the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Subscription billing | United States |
| Amazon Web Services | Infrastructure hosting | United States |
| Google LLC (Analytics) | Website analytics | United States |
SatsRail will notify the Controller before adding or replacing a sub-processor. The Controller may object within 15 days. If an objection cannot be resolved, the Controller may terminate the Agreement.
Personal Data is stored and processed in the United States. For transfers of Personal Data from the EEA to the United States, SatsRail relies on the EU-U.S. Data Privacy Framework, Standard Contractual Clauses (SCCs), or other appropriate safeguards as required by GDPR Chapter V.
In the event of a Personal Data breach, SatsRail shall notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach. The notification shall include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
SatsRail retains Personal Data as described in the Privacy Policy. Transaction data is retained for a minimum of 7 years for legal and tax compliance. Upon termination, Personal Data is deleted or returned within 90 days, except where legal retention obligations apply.
The Controller may audit SatsRail's compliance with this DPA once per year, with at least 30 days' written notice, during normal business hours, and at the Controller's expense. SatsRail may satisfy audit requests by providing relevant certifications, audit reports, or other documentation.
For questions about this DPA or to exercise rights under it, contact:
Version: 1.0 | Effective Date: March 27, 2026