Skip to main content
MavenPay
Data Processing

Data Processing Addendum

Effective 2026-06-08

  • Last updated ·
  • Effective from ·
The Short Version

This Data Processing Addendum forms part of the agreement between you, the Customer, and Maven Pay Inc., the Processor, where Maven Pay Inc. processes personal data on your behalf in connection with the MavenPay service. It applies in addition to our Privacy Policy and to any other agreement we have signed with you for the MavenPay service. Where this Addendum conflicts with the underlying agreement on a data-protection question, this Addendum prevails for that question.

1. Introduction

This Data Processing Addendum forms part of the agreement between you, the Customer, and Maven Pay Inc., the Processor, where Maven Pay Inc. processes personal data on your behalf in connection with the MavenPay service. It applies in addition to our Privacy Policy and to any other agreement we have signed with you for the MavenPay service. Where this Addendum conflicts with the underlying agreement on a data-protection question, this Addendum prevails for that question.

This Addendum is intended to meet the requirements of the General Data Protection Regulation (Regulation (EU) 2016/679), the United Kingdom General Data Protection Regulation, the Personal Information Protection and Electronic Documents Act of Canada, the Personal Data Protection Act of Singapore, the California Consumer Privacy Act as amended by the California Privacy Rights Act, and the equivalent data-protection laws of the jurisdictions where we serve.

2. Definitions

Customer means the natural person, business, or organisation that has entered into the underlying agreement with Maven Pay Inc. for the MavenPay service, acting as Controller of the Personal Data covered by this Addendum.

Processor means Maven Pay Inc. acting on the Customer's documented instructions.

Personal Data has the meaning given in the applicable data-protection law and refers to the personal data that the Customer makes available to the Processor in connection with the MavenPay service.

Sub-processor means any third party engaged by the Processor to process Personal Data on the Customer's behalf in the course of providing the MavenPay service.

Applicable Data Protection Law means the data-protection law of the jurisdictions identified in the introduction and any other law that applies to the processing in question.

3. Roles Of The Parties

For the personal data that the Customer makes available to Maven Pay Inc. in connection with the MavenPay service, the Customer is the Controller and Maven Pay Inc. is the Processor.

For the personal data that Maven Pay Inc. processes to meet its own regulatory and recordkeeping obligations as a regulated Canadian Payment Service Provider and a Money Services Business, Maven Pay Inc. is the Controller of that data, independent of any Customer instruction. Examples of this controller-data include identity-verification records that we are required by law to retain, sanctions-screening results, transaction-monitoring decisions, and suspicious-transaction reports.

4. Scope Of Processing

The Processor processes Personal Data only for the duration of the underlying agreement, for the purposes set out in the underlying agreement and in this Addendum, and on the Customer's documented instructions. The Customer's documented instructions include the underlying agreement, this Addendum, the Privacy Policy, the Acceptable Use Policy, the Customer's configuration of the MavenPay product, and any written instruction the Customer subsequently provides to the Processor.

The categories of Personal Data and the categories of Data Subjects processed under this Addendum are set out in Annex A.

The Processor will inform the Customer if, in the Processor's opinion, an instruction infringes Applicable Data Protection Law. The Processor is not required to act on an instruction that infringes Applicable Data Protection Law.

5. Confidentiality

The Processor will ensure that personnel authorised to process the Personal Data are subject to obligations of confidentiality that survive the end of the engagement.

6. Security

The Processor will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing. The measures are aligned with the controls published on the Maven Pay Trust Center at https://app.vanta.com/mavenpay.com/trust/lyjdri3s8ydg4qnc4uuq1. The Trust Center is the canonical live source of the technical and organisational measures in force. A categorical summary is set out in Annex B.

7. Sub-Processors

The Customer authorises the Processor to engage Sub-processors to process Personal Data on the Customer's behalf, subject to this section. The categorical list of Sub-processors is set out on our Sub-Processors page. The named list is shared with the Customer under this Addendum on request to compliance@mavenpay.com.

The Processor will impose on each Sub-processor data-protection obligations no less protective than those set out in this Addendum.

The Processor will give the Customer at least thirty days notice before adding or replacing a Sub-processor. If the Customer reasonably objects to the change on data-protection grounds within fifteen days of notification, the parties will work together in good faith to find a workable resolution. If no resolution is found, the Customer may terminate the underlying agreement for the part of the service that the change affects, on reasonable notice.

8. International Transfers

Where the Processor transfers Personal Data of a Data Subject in the European Economic Area, the United Kingdom, or Switzerland to a country outside the European Economic Area, the United Kingdom, or Switzerland that is not the subject of an adequacy decision, the transfer is subject to Standard Contractual Clauses approved by the European Commission, the United Kingdom International Data Transfer Addendum, and the Swiss Data Protection Authority's equivalent mechanism, respectively. The applicable module of the Standard Contractual Clauses is incorporated into this Addendum by reference.

For transfers from Canada to a country that does not provide a comparable level of protection, the Processor relies on contractual measures, on the Processor's own technical and organisational measures, and on the rights and remedies that this Addendum provides to the Data Subject.

9. Data Subject Requests

If the Processor receives a request from a Data Subject in respect of Personal Data processed on the Customer's behalf, the Processor will inform the Customer and will not respond to the request directly without the Customer's authorisation, unless the law requires the Processor to respond directly. The Processor will assist the Customer in responding to the request, taking into account the nature of the processing and the information available to the Processor.

10. Where Maven Pay Inc. Is Controller Of Its Own Regulatory Data

For the controller-data described under "Roles of the Parties", Data Subjects exercise their rights directly with Maven Pay Inc. as described in our Privacy Policy. The Customer does not have a right to direct Maven Pay Inc. on how to process this controller-data, and the Customer is not the appropriate addressee of a Data Subject request that relates to this controller-data.

11. Assistance To The Customer

The Processor will assist the Customer, taking into account the nature of the processing and the information available to the Processor, in meeting the Customer's own obligations under Applicable Data Protection Law in respect of security, breach notification, data-protection impact assessment, and prior consultation with a supervisory authority.

12. Breach Notification

The Processor will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data the Processor processes on the Customer's behalf. The notification will include the information available to the Processor at the time, including the nature of the breach, the categories of Personal Data and Data Subjects affected, the likely consequences, the measures taken or proposed to be taken in response, and the contact point for further information.

The Processor will provide further information as it becomes available, and will co-operate with the Customer in meeting the Customer's own breach-notification obligations under Applicable Data Protection Law.

13. Deletion Or Return Of Personal Data

On termination of the underlying agreement, the Processor will, at the Customer's choice, delete or return all Personal Data processed on the Customer's behalf and delete existing copies, unless Applicable Data Protection Law requires further storage of the Personal Data.

For controller-data described under "Roles of the Parties", the retention period set out in our Privacy Policy applies. Deletion of Personal Data does not affect the Processor's continued lawful retention of controller-data.

14. Audit

The Processor will make available to the Customer the information necessary to demonstrate compliance with this Addendum. The Processor's preferred way to evidence compliance is the Maven Pay Trust Center and the independent attestations referenced from it. Where the Customer is required by Applicable Data Protection Law to conduct an on-site audit, the parties will agree on the scope, timing, and conditions of the audit in advance, on reasonable notice, no more than once in a twelve-month period, and at the Customer's cost.

15. Liability Under This Addendum

The aggregate liability of each party arising out of or in connection with this Addendum is subject to the limitation of liability set out in the underlying agreement. The limitations do not apply to the extent the law prohibits their application.

16. Governing Law And Jurisdiction

This Addendum is governed by the law that governs the underlying agreement, except where Applicable Data Protection Law requires that a specific question be governed by the law of another jurisdiction, in which case the law required by Applicable Data Protection Law applies to that specific question.

17. Changes To This Addendum

We may update this Addendum from time to time. When we make a material change, we will tell you in the MavenPay product or by email at least thirty days before the change takes effect. The current version of this Addendum and its effective date are shown at the top of this page.

18. Contact

For any question about this Addendum, write to compliance@mavenpay.com.

For an executable, signed copy of this Addendum incorporating Standard Contractual Clauses, write to compliance@mavenpay.com with the Customer entity name and the address you want named in the Clauses.

19. Annex A — Categories Of Personal Data And Data Subjects

Categories of Data Subjects.

The Customer's end users where the Customer uses MavenPay as part of a service the Customer provides to its own end users. The Customer's employees, contractors, and authorised representatives. The Customer's payees, payors, suppliers, customers, and counterparties whose data the Customer makes available to the Processor in connection with a payment, a transfer, a card operation, or a crypto-asset operation.

Categories of Personal Data.

Identification data, including legal name, date of birth, residential address, country of citizenship, country of residence, and government-issued identity document details. Contact data, including email address, telephone number, and mailing address. Account data, including login identifier, password in hashed form, and account type. Transaction data, including amount, currency, counterparty identifier, timestamp, and origin and destination jurisdiction of payment instructions. Profile and device data, including IP address, device identifier, operating-system identifier, browser identifier, and timestamps of actions. Customer-service data, including the content and metadata of communications with the Processor's customer-service team. Travel and concierge data, where the Customer or its end user uses those services, including passenger name, date of birth, passport details, flight details, hotel details, and ground-transfer details. Mobile-connectivity data, where the Customer or its end user uses mobile top-up or eSIM services, including phone number, mobile operator, country, device identifier, and delivery timestamp.

20. Annex B — Technical And Organisational Measures (Categorical Summary)

Infrastructure security, including encryption of data in transit and at rest, key management, electronic-messaging protection, the protection of application-service transactions on public networks, and synchronised clocks across information-processing systems.

Organizational security, including ownership of assets, restrictions on software installation, acceptable-use rules for assets, planned operation and control of information-security processes, physical security perimeter, and protection against external and environmental threats.

Product security, including access control to program source code.

Internal security procedures, including information-systems audit controls, identification of applicable legislation and contractual requirements, periodic review of information-security policies, contact with authorities, mobile-device policy, an access-control policy, and the scope and operation of an information-security management system.

Data and privacy, including classification and labelling of information, handling of assets, management of removable media, physical media transfer, and information-transfer policies.

The live state of each control is published on the Maven Pay Trust Center at https://app.vanta.com/mavenpay.com/trust/lyjdri3s8ydg4qnc4uuq1.

Behind The Rail

Built On A Regulated Canadian Rail

Money Service Business🇨🇦C1000000640FINTRAC-registered
Payment Service Provider🇨🇦Supervised By Bank Of CanadaVerify on Bank of Canada
Reach

Questions about this document? Reach compliance@mavenpay.com.

Document version effective 2026-06-08. Last updated 2026-06-08. Prior versions available on request.