Home › Legal › Data Processing Agreement

Data Processing Agreement

Entity U.CASH Inc. Version 2026-08-06 Effective Aug 6, 2026

This Data Processing Agreement ("DPA") applies where you use the U.CASH Services as a merchant or business customer in a way that makes U.CASH a processor of personal data on your behalf. It is incorporated into the Terms of Service by reference.

For most personal data (such as your own account data), U.CASH acts as a controller under our Privacy Policy. This DPA applies only to personal data you control that U.CASH processes to provide a Service to you (for example, your customers' data that flows through a checkout or store you operate).

1. Roles and scope

You are the "Customer" and, for the personal data described in this DPA, the "controller" or "business" (under the CCPA). U.CASH Inc. is the "processor" or "service provider". U.CASH will process Customer personal data only on your documented instructions and for the purpose of providing the Services.

2. Details of processing

  • Categories of data subjects: your customers and end users.
  • Categories of personal data: contact details, wallet addresses, transaction metadata, and order information that you submit or that is generated in the course of providing the Service.
  • Nature and purpose: operating the Service you selected (for example payment links, checkout, or storefront).
  • Retention: as needed to provide the Service and as required by law, after which data is deleted or returned as set out below.

3. Sub-processors

We engage sub-processors listed below under written contracts that impose confidentiality and security obligations no less protective than this DPA. We will give notice of new or replacement sub-processors and you may object on reasonable grounds.

Sub-processorPurposeLocationTransfer basis
Cloud hosting providerHosting and databasesCanada / United StatesSCCs / adequacy
Email delivery providerTransactional emailUnited StatesSCCs
Analytics provider (opt-in)Aggregated measurementUnited StatesSCCs
DEX aggregators (on-chain)Swap and buy routingDecentralizedn/a (no personal data)
Unstoppable Domains / FIODomain registrationUnited StatesTheir terms

List last reviewed: August 2026. The current list is maintained alongside this DPA and updated as providers change.

4. Security measures

We implement technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls on a least-privilege basis, logging, and monitoring. See our Responsible Disclosure and Security page. Because U.CASH is non-custodial, we never hold your customers' funds or private keys.

5. International transfers

Where personal data is transferred out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, an adequacy decision, or another lawful transfer mechanism, and we complete a transfer impact assessment where required.

6. Personal data breach

We will notify you without undue delay, and in any case within 72 hours of becoming aware, of a personal data breach affecting your data, and will provide the information reasonably needed for you to meet your own notification obligations.

7. Your rights assistance and audit

We will assist you, where reasonably possible, in responding to data-subject rights requests and in meeting your obligations regarding security, breach notification, and data-protection impact assessments. You may audit our compliance with this DPA through our attestations and reports; we will provide reasonable cooperation.

8. Deletion and return

On termination of the relevant Service, we will, at your choice, delete or return Customer personal data, and delete existing copies, unless retention is required by law.

9. Term

This DPA runs alongside the Terms for as long as U.CASH processes Customer personal data on your behalf, and the confidentiality and security obligations survive termination.

← Back to Legal  ·  Back to top