1. Introduction and Scope
This Data Processing Agreement (“DPA”) forms part of the agreement between the business Client (“you,” “your,” the “Client,” or “Controller”) and Fyatu Financial Technologies Limited (“Fyatu,” “we,” “us,” or “Processor”) and governs the processing of personal data by Fyatu on your behalf in connection with the Fyatu card issuing platform (the “Services”).
This DPA applies where Fyatu processes personal data for which you are the controller. It supplements, and must be read together with, the Terms of Service and the Privacy Policy. In the event of a conflict between this DPA and those documents in respect of the processing of personal data, this DPA prevails.
2. Definitions
Terms such as “personal data,” “processing,” “controller,” “processor,” “data subject,” “personal data breach,” and “supervisory authority” have the meanings given in applicable data protection law. “Applicable Data Protection Law” means all data protection and privacy laws applicable to the processing of personal data under the Services, including, where relevant, the EU General Data Protection Regulation (GDPR) and equivalent national laws.
3. Roles of the Parties
For personal data relating to your Cardholders and end users processed through the Services, you are the Controller and Fyatu is the Processor. You determine the purposes and means of the processing; Fyatu processes personal data only on your documented instructions, as set out in this DPA and the Services.
Fyatu acts as a separate, independent controller for the limited personal data it processes for its own purposes — such as account administration, billing, fraud prevention, security, and compliance with its own legal obligations — as described in the Privacy Policy.
4. Subject Matter, Nature and Purpose of Processing
- Subject matter: provision of card issuing and programme management services.
- Nature and purpose: onboarding Cardholders, issuing and managing Cards, authorising and settling transactions, KYC/AML screening (as applicable to your KYC mode), fraud prevention, reporting, and support.
- Duration: for the term of the agreement and as set out in Section 13.
5. Categories of Data Subjects and Personal Data
| Category of data subject | Types of personal data |
|---|---|
| Your Cardholders | Name, email, phone, date of birth, address, nationality, identity document details, cardholder reference, and, under Managed or Shared KYC, verification documents and results |
| Your authorised users | Name, email, role, and authentication data |
| Transacting individuals | Transaction metadata (amount, merchant, MCC, timestamps) associated with Cards |
You must not instruct Fyatu to process special categories of personal data except where strictly necessary for identity verification and permitted by Applicable Data Protection Law.
6. Fyatu’s Obligations as Processor
Fyatu shall:
- Process personal data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case it will inform you unless legally prohibited);
- Ensure that persons authorised to process personal data are bound by confidentiality;
- Implement appropriate technical and organisational security measures (Section 8);
- Respect the conditions in Section 9 for engaging sub-processors;
- Assist you, taking into account the nature of the processing, in responding to data subject requests (Section 10) and in ensuring compliance with your obligations regarding security, breach notification, and data protection impact assessments;
- Notify you without undue delay of a personal data breach (Section 11); and
- At your choice, delete or return personal data at the end of the Services (Section 13).
7. Your Obligations as Controller
You shall:
- Establish and maintain a lawful basis for the processing and ensure appropriate notices and consents are in place with your Cardholders and end users;
- Provide only documented, lawful instructions for the processing; and
- Perform and evidence Cardholder KYC/AML consistent with your KYC mode, including full responsibility for verification under Shared and Minimal modes.
8. Security Measures
Fyatu maintains appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, including: encryption of data in transit and at rest; access controls and least-privilege access; network segregation and secure infrastructure; logging and monitoring; PCI DSS-aligned handling of card data (Fyatu does not store raw PANs on its infrastructure); and regular review of its security controls.
9. Sub-processors
You provide general authorisation for Fyatu to engage sub-processors to deliver the Services, including the BIN Sponsor, card networks, KYC/identity-verification providers, cloud infrastructure, communications, and analytics providers. Fyatu imposes data protection obligations on each sub-processor that are no less protective than those in this DPA and remains responsible for their performance. Fyatu will inform you of intended changes to sub-processors and give you the opportunity to object on reasonable data-protection grounds.
10. Assistance with Data Subject Rights
Taking into account the nature of the processing, Fyatu shall assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights (including access, rectification, erasure, restriction, portability, and objection). Where a data subject contacts Fyatu directly regarding data processed on your behalf, Fyatu will refer the request to you.
11. Personal Data Breach Notification
Fyatu shall notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf, and shall provide sufficient information to enable you to meet any obligations to report the breach to a supervisory authority or affected data subjects. Notifications are sent to your registered contact and dedicated Slack channel.
12. International Data Transfers
Where the provision of the Services involves the transfer of personal data across borders, Fyatu shall ensure that such transfers are carried out in accordance with Applicable Data Protection Law, including through the use of appropriate safeguards (such as standard contractual clauses) where required.
13. Return and Deletion of Personal Data
On termination or expiry of the Services, Fyatu shall, at your choice, delete or return the personal data processed on your behalf and delete existing copies, unless retention is required by law or by the BIN Sponsor or card network for regulatory, audit, or fraud-prevention purposes, in which case Fyatu will retain it only for as long as required and continue to protect it under this DPA.
14. Audits and Inspections
Fyatu shall make available to you information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, subject to reasonable notice, confidentiality, and frequency limits, and conducted so as not to disrupt Fyatu’s operations or compromise the security of other clients.
15. Liability
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
16. Duration
This DPA takes effect when you accept it during onboarding or begin using the Services, and remains in force for as long as Fyatu processes personal data on your behalf.
17. Contact
For data protection inquiries or to exercise rights under this DPA:
- Data protection / privacy: [email protected]
- Platform support: [email protected]