Policies

Update – July 10, 2026

Data Processing Addendum (DPA)

Rebill - Merchant Agreement

CONTROLLER / MERCHANT PROCESSOR / REBILL EFFECTIVE DATE
The entity identified as Merchant in the applicable Service Agreement. Rebill, acting through the applicable contracting entity identified in the Service Agreement. Concurrent with the execution or acceptance of the applicable Service Agreement

A. Recitals

This Data Processing Addendum ("DPA") supplements and forms part of the General Terms and Conditions, Merchant Agreement, Service Agreement, order form, statement of work, or other written agreement governing Merchant access to and use of Rebill services (collectively, the "Service Agreement").

The parties acknowledge that, in the context of the Services, the Merchant may collect Personal Data directly from payers or other end users and transmit such Personal Data to Rebill through API integrations, hosted payment flows, dashboards, support channels, or other agreed technical means.

For the Processor Services described in this DPA, Merchant acts as Controller and Rebill acts as Processor. The parties further acknowledge that Rebill may act as an independent Controller for certain activities that Rebill determines and performs to comply with applicable law, financial regulation, anti-money laundering obligations, sanctions screening, fraud and risk controls, tax and accounting requirements, payment network rules, disputes, chargebacks, legal claims, and regulatory reporting.

This DPA incorporates by reference Rebill's Privacy Policy, to the extent applicable. If there is a conflict between this DPA and the Privacy Policy with respect to Rebill's Processor obligations, this DPA prevails. If there is a conflict between this DPA and the Service Agreement regarding data protection matters, this DPA prevails; otherwise, the Service Agreement prevails.

Term Definition
Applicable Data Protection Law All laws and regulations applicable to the Processing of Personal Data under the Service Agreement, including, where applicable, the GDPR, UK GDPR, Brazilian LGPD, Colombian Law 1581/2012 and its implementing rules, Mexican LFPDPPP and its regulations, Argentine Law 25.326, Uruguayan Law 18.331, Chilean data protection laws, and any successor or implementing regulations.
Cardholder Data Payment card data as defined under the applicable PCI DSS rules, including primary account number (PAN) and associated cardholder data elements.
Controller The party that determines the purposes and means of Processing Personal Data. For Processor Services, Merchant is the Controller.
Data Breach A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Rebill as Processor.
Data Subject An identified or identifiable natural person to whom Personal Data relates, including Merchant customers, payers, representatives, beneficial owners, and users where applicable.
Treatment as an Independent Data Controller Processing carried out by Rebill as an independent Controller for its own legal, regulatory, risk, security, payment network, tax, accounting, fraud prevention, dispute, or compliance purposes.
Personal Information Any information relating to an identified or identifiable natural person, including the Personal Data of the Store's Customers.
Treatment Any operation or set of operations performed on Personal Data, including collection, receipt, storage, use, disclosure, transmission, restriction, retention, deletion, and return.
Property Manager Services Services in connection with which Rebill processes the Merchant’s Customers’ Personal Data on behalf of the Merchant and in accordance with the Merchant’s documented instructions, as described in Annex 1.
Security Incident Any unauthorized access, loss, disclosure, alteration, or destruction—whether actual or reasonably suspected—of Personal Data, or any compromise of the systems used to process Personal Data.
Sub-processor A third party engaged by Rebill to process the Merchant’s Customers’ Personal Data on behalf of the Merchant in connection with the Administrator Services.

2. Scope and Assignment of Roles

2.1 This DPA applies to Rebill's Processing of Merchant Customer Personal Data as Processor in connection with the Processor Services. The details of such Processing are set out in Schedule 1

2.2 The parties agree that Merchant is responsible for determining the purposes and lawful basis for collecting and transmitting Merchant Customer Personal Data to Rebill for the Processor Services.

2.3 Rebill will process Merchant Customer Personal Data as Processor only on Merchant's documented instructions, including the Service Agreement, this DPA, Merchant's configuration of the Services, and Merchant's use of the applicable API, dashboard, or operational workflow, unless Rebill is required to process such Personal Data by applicable law.

2.4 Independent Controller Processing. Notwithstanding anything to the contrary, Rebill acts as an independent Controller where it processes Personal Data to comply with applicable law, financial regulation, AML/KYC obligations, sanctions screening, fraud and risk controls, payment network and card scheme rules, dispute and chargeback management, tax and accounting requirements, security monitoring, regulatory reporting, audits, or legal claims. Such Processing is not performed on Merchant's documented instructions, and Rebill is independently responsible for complying with Applicable Data Protection Law in relation to such Processing.

2.5 No sale of Personal Data. Rebill will not sell Merchant Customer Personal Data or use it for cross-context behavioral advertising or unrelated marketing purposes, except where expressly authorized by Merchant or permitted by Applicable Data Protection Law.

3. Merchant Obligations

3.1 Merchant shall comply with Applicable Data Protection Law in its capacity as Controller, including by providing all required notices and obtaining all required consents or other lawful bases before collecting or transmitting Personal Data to Rebill.

3.2 Merchant shall ensure that its privacy notices disclose the use of Rebill and relevant third parties for payment processing, fraud prevention, risk controls, customer support, regulatory compliance, and other purposes reasonably necessary to provide the Services.

3.3 Merchant shall not instruct Rebill to process Personal Data in a manner that would violate Applicable Data Protection Law, payment network rules, PCI DSS requirements, financial regulation, AML/KYC rules, or the Service Agreement.

3.4 Merchant is responsible for the accuracy, quality, and legality of Personal Data transmitted to Rebill and shall promptly notify Rebill of any material inaccuracy or unauthorized disclosure of Personal Data that may affect the Services.

3.5 Merchant shall not transmit special categories of Personal Data, sensitive Personal Data, or regulated data beyond what is necessary for the Services unless expressly agreed in writing and supported by an applicable lawful basis.

4. Rebill Processor Obligations

4.1 Documented instructions. Rebill shall process Merchant Customer Personal Data as Processor only on documented instructions from Merchant, unless required by applicable law. If Rebill is legally required to process Personal Data outside Merchant's instructions, Rebill shall notify Merchant before such Processing unless legally prohibited.

4.2 Confidentiality and access. Rebill shall ensure that personnel authorized to process Merchant Customer Personal Data are subject to appropriate confidentiality obligations and that access is limited to personnel and systems with a legitimate need to perform the Services.

4.3 Security measures. Rebill shall implement and maintain appropriate technical and organizational measures designed to protect Merchant Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, alteration, or disclosure. Such measures shall include, as applicable, the controls described in Schedule 3.

4.4 PCI and card data. To the extent Rebill processes Cardholder Data, Rebill shall maintain controls designed to comply with applicable PCI DSS requirements for its role. Rebill shall not store card verification codes, CVV, CVC, CID, PINs, or full magnetic stripe data after authorization, even if encrypted, except to the extent expressly permitted by applicable PCI DSS rules.

4.5 Data subject requests. Taking into account the nature of the Processing, Rebill shall provide reasonable assistance to Merchant to respond to requests by Data Subjects exercising rights under Applicable Data Protection Law. If Rebill receives a request directly relating to Merchant Customer Personal Data processed as Processor, Rebill shall, unless legally prohibited, promptly redirect or forward the request to Merchant.

4.6 DPIAs and consultations. Rebill shall provide reasonable assistance to Merchant for data protection impact assessments and prior consultations with supervisory authorities, to the extent required by Applicable Data Protection Law and related to Rebill's Processing as Processor.

4.7 Unlawful instructions. If Rebill reasonably believes that an instruction infringes Applicable Data Protection Law, Rebill shall notify Merchant and may suspend the affected Processing until the parties resolve the issue.

5. Sub-processors

5.1 Merchant grants Rebill general written authorization to engage Sub-processors to provide the Processor Services, subject to the requirements in this Section 5.

5.2 Rebill shall maintain a list of authorized Sub-processors, including name, purpose, processing location, and relevant transfer mechanism where reasonably available. The current list shall be provided in Schedule 2, through a Rebill sub-processor webpage, or upon Merchant's written request.

5.3 Rebill shall impose written data protection obligations on each Sub-processor that are no less protective than those set out in this DPA, to the extent applicable to the nature of the services provided by the Sub-processor.

5.4 Rebill shall provide Merchant with at least thirty (30) days' prior notice before adding or replacing a Sub-processor where required by Applicable Data Protection Law or where the change is material to the Processor Services. Merchant may object on reasonable data protection grounds within fifteen (15) days after notice.

5.5 If the parties cannot resolve a timely and reasonable objection, Merchant may terminate the affected Processor Services without penalty upon thirty (30) days' written notice. This remedy applies only to the affected Processing activities and does not relieve Merchant of payment obligations accrued before termination.

5.6 Rebill remains responsible to Merchant for the acts and omissions of Sub-processors to the same extent Rebill would be responsible if performing the Processor Services directly, subject to the limitations of liability in the Service Agreement and this DPA.

6. Security Incidents and Data Breach Notification

6.1 Rebill shall notify Merchant without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of a Data Breach affecting Merchant Customer Personal Data processed by Rebill as Processor. Rebill may provide an initial notice based on reasonably available information and supplement it as the investigation progresses. A delay in notification that does not materially prejudice Merchant shall not, by itself, constitute a breach of this DPA.

6.2 The notice shall include, to the extent reasonably available: (a) a description of the nature of the Data Breach; (b) categories and approximate number of affected Data Subjects and records; (c) likely consequences; (d) measures taken or proposed to address and mitigate the Data Breach; and (e) contact details for Rebill's security or data protection point of contact.

6.2 The notice shall include, to the extent reasonably available: (a) a description of the nature of the Data Breach; (b) categories and approximate number of affected Data Subjects and records; (c) likely consequences; (d) measures taken or proposed to address and mitigate the Data Breach; and (e) contact details for Rebill's security or data protection point of contact.

6.4 Notification under this Section 6 does not constitute an admission of fault, liability, or violation of law.

7. International Data Transfers

7.1 Merchant Customer Personal Data may be transferred to or processed in countries other than the country where Merchant or Data Subjects are located, including countries where Rebill, its affiliates, acquirers, financial institutions, cloud providers, fraud prevention providers, KYC/AML providers, support platforms, and other Sub-processors operate.

7.2 Where a transfer of Personal Data is subject to cross-border transfer restrictions, Rebill shall ensure that an appropriate transfer mechanism is in place, such as an adequacy decision, standard contractual clauses, binding corporate rules, certification, consent, necessity derogation, or other mechanism recognized under Applicable Data Protection Law.

7.3 For transfers of Personal Data from the European Economic Area, United Kingdom, or Switzerland to a country not recognized as providing adequate protection, the parties shall rely on the applicable standard contractual clauses or equivalent mechanism, as amended or replaced from time to time, and the relevant module shall apply according to the parties' roles.

7.4 For transfers of Personal Data from Brazil subject to the LGPD’s international transfer restrictions, the parties shall apply a transfer mechanism recognized by the ANPD, including the standard contractual clauses approved by the ANPD when required. When such clauses are required, they shall be incorporated in their entirety and without alteration, except for permitted editable fields.

7.5 Upon Merchant's reasonable written request, Rebill shall provide information regarding the transfer mechanisms applicable to the Processor Services, subject to confidentiality, security, and legal restrictions.

8. Audit and Compliance Verification

8.1 Upon reasonable written request, Rebill shall make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of security policies, third-party certifications, attestations, PCI DSS evidence, SOC 2, ISO 27001, penetration test executive summaries, or equivalent materials where available and relevant.

8.2 Merchant may request an on-site or independent audit no more than once per calendar year, and only where the information, reports, certifications, and attestations made available under Section 8.1 are reasonably insufficient to demonstrate compliance, unless an audit is required by a supervisory authority or follows a material Data Breach affecting Merchant Customer Personal Data. Any audit shall be subject to at least thirty (30) days' prior written notice, reasonable scope, confidentiality, security restrictions, and Rebill's policies designed to protect its systems, other customers, and sensitive information.

8.3 The parties shall agree in writing on the scope, timing, duration, and auditor. Rebill may reject an auditor that is a competitor, lacks appropriate qualifications, or presents a conflict of interest, in which case the parties shall cooperate to select an alternative auditor.

8.4 Where Rebill provides a current third-party audit report, certification, or attestation covering the relevant Processing, such materials shall satisfy the audit requirement unless Merchant demonstrates that additional audit activity is legally required or reasonably necessary.

8.5 Audits shall be conducted at Merchant's expense and shall not unreasonably disrupt Rebill's business operations. Audits may not include direct access to production systems, source code, other customers' data, privileged legal advice, or highly sensitive security information.

9. Retention, Return, and Deletion

9.1 Rebill shall retain Merchant Customer Personal Data for the duration of the Service Agreement and for any additional period required or permitted by Applicable Data Protection Law, financial regulation, AML/KYC obligations, tax and accounting rules, card scheme requirements, dispute and chargeback rules, audit requirements, or legal claims.

9.2 Upon termination or expiration of the Service Agreement, and subject to legally required or permitted retention, Rebill shall, at Merchant's written election, return or securely delete Merchant Customer Personal Data processed exclusively as Processor. Rebill shall confirm completion within sixty (60) days after Merchant's written request, unless retention is required or permitted by law.

9.3 Where Rebill retains Personal Data after termination for Independent Controller Processing or legal retention purposes, it shall process such data only for those purposes and maintain appropriate security measures.

9.4 Backups. Personal Data stored in routine backups shall be deleted or overwritten in accordance with Rebill's standard backup lifecycle, provided that such data remains protected and is not restored except as necessary for disaster recovery, security, legal, or compliance purposes.

9.5 Additional retention details are set out in Schedule 4. If Schedule 4 conflicts with mandatory law, the mandatory legal retention period prevails.

10. Liability

10.1 Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Service Agreement, except to the extent prohibited by Applicable Data Protection Law. For the avoidance of doubt, the aggregate liability caps in the Service Agreement and this DPA apply together and not independently, such that the total aggregate liability of either party across both instruments shall not exceed the highest applicable cap set out in the Service Agreement.

10.2 To the extent permitted by applicable law, Rebill’s total aggregate liability to Merchant under or in connection with this DPA shall not exceed fifty percent (50%) of the total fees paid by Merchant to Rebill in the twelve (12) months preceding the event giving rise to the claim.

10.3 The limitations in this Section 10 do not apply to liability arising from a party’s gross negligence or willful misconduct, or to claims that cannot be limited under Applicable Data Protection Law.

11. Term

11.1 This DPA commences on the effective date of the Service Agreement and remains in force for as long as Rebill processes Merchant Customer Personal Data on behalf of Merchant or as otherwise required by Applicable Data Protection Law.

11.2 Termination or expiration of this DPA does not affect rights or obligations accrued before termination and does not affect provisions intended to survive, including Sections 7, 8, 9, 10, 12, and 13.

12. Governing Law and Jurisdiction

12.1 This DPA is governed by the laws specified in the Service Agreement. If the Service Agreement does not specify governing law, this DPA is governed by the laws of the Republic of Argentina, without regard to conflict of law principles.

12.2 Any dispute arising out of or in connection with this DPA shall be subject to the dispute resolution forum specified in the Service Agreement. If none is specified, the parties submit to the exclusive jurisdiction of the competent courts of the City of Buenos Aires, Argentina.

13. General Provisions

13.1 Entire agreement. This DPA, together with the Service Agreement and incorporated documents, constitutes the entire agreement between the parties regarding Rebill's Processing of Merchant Customer Personal Data as Processor.

13.2 Amendments. Rebill may amend this DPA upon thirty (30) days' prior written notice where the amendment is required to comply with changes in Applicable Data Protection Law, payment network rules, regulatory obligations, security requirements, or material changes in the Services. For other amendments, the parties' written agreement is required.

13.3 Severability. If any provision of this DPA is invalid or unenforceable, it shall be modified to the minimum extent necessary to make it valid and enforceable, and the remaining provisions shall remain in effect.

13.4 Order of precedence. In case of conflict regarding data protection matters, this DPA prevails over the Service Agreement unless the Service Agreement expressly states that it overrides this DPA. In all other matters, the Service Agreement prevails.

13.5 No third-party beneficiaries. Except where required by Applicable Data Protection Law or incorporated transfer clauses, this DPA does not create rights for third parties.

14. Execution

This DPA is incorporated into and forms an integral part of the Service Agreement between the parties. It may be executed electronically, through incorporation by reference, or by signature below, as permitted by the Service Agreement and applicable law.

FOR THE CONTROLLER / MERCHANT FOR THE PROCESSOR / REBILL
Signature: ____________________________ Signature: ____________________________
Name: ___________________________ Name: ___________________________
Title: ____________________________ Title: ____________________________
Date: ____________________________ Date: ____________________________

Schedule 1. Details of Processing

Processing element
Description
Purpose Provision of payment processing, payment orchestration, transaction routing, authorization support, fraud prevention support, reporting, reconciliation, settlement support, customer support, and related services under the Service Agreement.
Nature and Purpose of the Processing Receiving, validating, transmitting, tokenizing, storing, securing, analyzing, reconciling, reporting, and deleting Personal Data as necessary to provide the Services, support Merchant, manage payment flows, prevent fraud, and maintain platform security.
Categories of Data Subjects Merchant customers, payers, users, buyers, subscribers, authorized representatives, support contacts, beneficial owners, and other individuals whose Personal Data is transmitted to Rebill in connection with the Services.
Categories of Personal Data Identification data such as name, email, phone number, national ID or tax ID where required; transaction data such as amount, currency, merchant, country, transaction identifiers, payment method, status, refunds, disputes, chargebacks; technical data such as IP address, device ID, device fingerprint, browser metadata, logs, risk signals; payment data such as PAN or tokenized PAN, cardholder name, expiration date, billing address, authorization response and payment tokens; support data and communications.
Sensitive authentication data CVV/CVC/CID, PINs, and full magnetic stripe or equivalent sensitive authentication data are processed only transiently where necessary for authorization and are not stored after authorization, except where expressly permitted by applicable PCI DSS rules.
Special Categories / Sensitive Data Not intentionally processed as part of the standard Services unless expressly agreed in writing and supported by Applicable Data Protection Law.
Duration of Processing For the term of the Service Agreement plus any retention period required or permitted by law, financial regulation, AML/KYC obligations, tax/accounting rules, card scheme requirements, disputes, chargebacks, audits, or legal claims.
Frequency of Processing Continuous or as initiated by Merchant, payers, payment networks, acquirers, processors, banks, fraud providers, KYC/AML providers, support channels, or platform events.
Merchant instructions
The Service Agreement, this DPA, Merchant configuration, API calls, dashboard operations, support requests, and other documented instructions accepted by Rebill.

Schedule 2. Authorized Sub-processors and Transfer Overview

Rebill uses Sub-processors in the categories below to provide the Services. Provider names, processing locations, and transfer mechanisms may vary by country, payment method, and product configuration. Rebill will make the current Sub-processor list available upon written request, through a Rebill sub-processor webpage, or under confidentiality where appropriate.

Category Purpose Provider names Processing locations Transfer Mechanism
Cloud Infrastructure and Hosting Providers Hosting, compute, storage, database, network security, backup, logging Provider names available upon request or via Rebill sub-processor list Licensed acquirers, payment processors, card networks, banks, and financial institutions SCC, ANPD SCC, compliance, DPA, or other applicable mechanism
Licensed acquirers, payment processors, card networks, banks, and financial institutions Authorization, clearing, settlement, payouts, chargebacks, dispute management, regulatory/payment network obligations Country-specific provider names available upon request or via Rebill sub-processor list Countries where payment services are provided and cross-border payment partners operate Requirement under local law, SCC/SCC of the ANPD when required, financial regulatory requirement, DPA
Fraud prevention and risk management providers Fraud scoring, device fingerprinting, risk signals, transaction monitoring Provider names available upon request or via Rebill sub-processor list Provider locations and processing regions SCC, ANPD SCC, DPA, or another applicable mechanism
Identity verification and KYC/AML providers Identity verification, sanctions/PEP screening, onboarding support, regulatory compliance Provider names available upon request or via Rebill sub-processor list Provider locations and processing regions SCC, ANPD SCC, legal/regulatory requirement, DPA, or other applicable mechanism
Merchant onboarding and lifecycle tools Merchant onboarding, KYB, CRM, operational workflows Provider names available upon request or via Rebill sub-processor list Provider locations and processing regions SCC, ANPD SCC, DPA, or another applicable mechanism
Customer Support and Communications Platforms Support ticketing, notifications, email/SMS/WhatsApp or other communications Provider names available upon request or via Rebill sub-processor list Provider locations and processing regions SCC, ANPD SCC, DPA, or another applicable mechanism

Schedule 3. Technical and Organizational Measures

Control Area Measurements
Governance Documented information security and privacy policies; assigned security/privacy ownership; periodic policy review; confidentiality obligations for personnel.
Access Controls Role-based access control; least privilege; unique user accounts; access reviews; prompt deprovisioning; MFA for administrative and sensitive systems where available.
Encryption and Key Management Encryption of Personal Data in transit using industry-standard protocols; encryption at rest for databases, storage, and backups where technicallyfeasible; restricted key access and managed key rotation where applicable.

Network and Infrastructure Security Segregated environments; firewalls/security groups; hardened cloud configuration; monitoring of critical systems; vulnerability management and patching based on risk.
Application Security Secure development practices; code review for material changes; dependency management; secrets management; testing before production deployment; logging and monitoring of security-relevant events
PCI DSS Controls Controls designed to meet applicable PCI DSS requirements for Rebill's role, including protection of Cardholder Data, PAN masking/tokenization where applicable, and prohibition on post-authorization storage of sensitive authentication data.
Incident Response Incident response process; escalation procedures; investigation, containment, remediation, and post-incident review; breach notification workflow aligned with this DPA.
Data Minimization and Retention Collection and retention limited to what is necessary for the Services, legal/regulatory obligations, payment network requirements, security, fraud prevention, disputes, and legal claims.
Vendor management Due diligence of material Sub-processors; written data protection obligations; review of security and privacy posture based on risk and role.
Business Continuity Backups, restoration procedures, disaster recovery and business continuity measures proportionate to the nature of the Services
Physical Security Reliance on cloud provider and office physical security controls, as applicable, plus restricted access to facilities where company-managed systems or records are located.
Training and Awareness Security/privacy onboarding and periodic awareness for personnel with access to Personal Data.

Schedule 4. Retention Framework

Data Category Conservation Approach Main Rationale
Transaction Records As required or permitted by financial regulation, tax/accounting rules, card scheme requirements, dispute/chargeback deadlines, AML/KYC obligations, audits, and legal claims; commonly up to ten (10) years depending on jurisdiction and record type. Financial regulation, tax/accounting, AML/KYC, disputes, card scheme rules, audit, legal claims
PAN / tokenized card data Only as necessary and permitted under PCI DSS, payment network rules, and the Service Agreement. Stored PAN, where retained, must be protected, masked, tokenized, encrypted, or rendered unreadable as required by PCI DSS. Payment processing, recurring payments, disputes, security, PCI DSS
CVV/CVC/CID, PIN, full magnetic stripe, or equivalent sensitive authentication data Not stored after authorization, even if encrypted, except where expressly permitted by applicable PCI DSS rules. PCI DSS and payment network compliance
Device fingerprint, IP address, browser metadata, and risk signals For the period reasonably necessary for fraud prevention, security monitoring, risk modeling, disputes, compliance, and legal claims, subject to applicable law and Rebill's retention policies. Fraud/risk, security, dispute management, compliance
KYC/KYB/AML and sanctions records As required or permitted by applicable AML/KYC, financial regulation, sanctions screening, regulatory reporting, audit, and legal claims requirements AML/KYC, sanctions, financial regulation, legal claims
Support and Communications Records For the period reasonably necessary to provide support, evidence Merchant instructions, resolve disputes, improve service quality, and comply with legal obligations. Customer support, disputes, service quality, legal claims
Backups and Logs Retained according to Rebill's backup and logging lifecycle, then overwritten or deleted in the ordinary course, unless legally required to preserve them. Security, Resilience, Auditing, Disaster Recovery

Of interest: