Last updated:
Merchant Data Processing Addendum
Controller-processor terms for merchant customer data processed through SenteRail.
This Addendum gives SenteRail a merchant-facing processor framework for merchant customer data while expressly preserving SenteRail's independent-controller processing for fraud, legal compliance, security, audit, and redress functions.
Read this Addendum together with our Privacy Policy and Merchant Terms.
When this addendum applies
This Merchant Data Processing Addendum applies where a merchant, partner, or institutional customer uses SenteRail to process personal data and, for the relevant data set and use case, SenteRail acts as a processor or service provider on behalf of that customer.
This Addendum does not limit processing that SenteRail performs as an independent controller for fraud prevention, sanctions screening, legal retention, security, complaints handling, audit, regulatory reporting, or enforcement of SenteRail's contractual rights.
Roles of the parties
The merchant is responsible for determining the lawful basis and purpose for the collection and disclosure of merchant customer data submitted to SenteRail for payment processing and related merchant services. To the extent SenteRail processes that data on the merchant's behalf for merchant-directed service delivery, SenteRail acts as processor and the merchant acts as controller.
Merchant instructions
SenteRail will process merchant customer data only on documented merchant instructions as reflected in the service configuration, API requests, dashboard settings, support instructions, and the underlying service agreement, except where SenteRail is required or permitted by law to process the data for its own independent compliance or security purposes.
The merchant must not instruct SenteRail to process data unlawfully or in a way that infringes the rights of data subjects or third parties.
Merchant obligations
The merchant must:
- provide required privacy notices and lawful grounds for disclosure to SenteRail;
- ensure the data submitted is relevant, accurate, and not excessive for the intended purpose;
- respond to data subject requests concerning the merchant's own processing obligations;
- configure and use the Services in a manner consistent with applicable law;
- notify SenteRail of any unlawful instruction or known data accuracy issue affecting the Services.
SenteRail security measures
SenteRail will maintain reasonable technical and organizational measures designed to protect merchant customer data against unauthorized access, unlawful disclosure, misuse, alteration, and loss, taking into account the nature of the data and the risks presented by processing in a payments and financial infrastructure environment.
These measures may include access controls, authentication controls, environment segregation, audit logging, secure secret handling, encryption where appropriate, backup controls, vulnerability management, and incident response procedures.
Subprocessors and third-party recipients
The merchant authorizes SenteRail to use subprocessors and supporting service providers where reasonably necessary to deliver the Services, including infrastructure, messaging, analytics, support, identity, tax, and payment rail providers. SenteRail remains responsible for managing those providers in a manner appropriate to the risk and service context.
SenteRail may also disclose data to banks, mobile money operators, tax authorities, regulators, courts, law enforcement, or other competent authorities where necessary for transaction execution, legal compliance, or protection of rights and interests.
Data subject requests and cooperation
Where SenteRail receives a request from a data subject that appears to relate to data the merchant controls, SenteRail may redirect the request to the merchant or notify the merchant as appropriate, unless SenteRail is legally required to respond directly. SenteRail will provide reasonable assistance, taking into account the nature of the processing and the information available to SenteRail.
Security incidents and breach response
SenteRail will take reasonable steps to investigate and contain a confirmed or reasonably suspected security incident affecting merchant customer data. Where notification to the merchant is legally required or reasonably necessary for coordinated response, SenteRail will provide notice without undue delay, subject to lawful confidentiality, evidentiary, and security constraints.
Cross-border transfers and location of processing
Merchant customer data may be processed in Uganda or in other jurisdictions where SenteRail or its subprocessors operate. SenteRail will take reasonable steps to ensure that any cross-border processing is conducted with safeguards appropriate to the data and permitted by applicable law.
Retention, return, and deletion
SenteRail will retain merchant customer data only for as long as reasonably necessary for service delivery, support, complaints, reconciliation, fraud handling, and lawful retention obligations. Upon termination or on written request, SenteRail may delete or anonymize merchant customer data unless continued retention is required for legal, regulatory, evidentiary, tax, security, or legitimate business reasons.
Audit and information rights
Where reasonably necessary and proportionate to the risk, SenteRail may provide information about its relevant technical and organizational measures, subject to confidentiality, privilege, system security, and third-party restrictions. On-site audits are not permitted unless required by law or separately agreed in writing.