A. Recitals
This Data Processing Addendum ("DPA") supplements and forms part of the General Terms and Conditions, Merchant Agreement, Service Agreement, order form, statement of work, or other written agreement governing Merchant access to and use of Rebill services (collectively, the "Service Agreement").
The parties acknowledge that, in the context of the Services, the Merchant may collect Personal Data directly from payers or other end users and transmit such Personal Data to Rebill through API integrations, hosted payment flows, dashboards, support channels, or other agreed technical means.
For the Processor Services described in this DPA, Merchant acts as Controller and Rebill acts as Processor. The parties further acknowledge that Rebill may act as an independent Controller for certain activities that Rebill determines and performs to comply with applicable law, financial regulation, anti-money laundering obligations, sanctions screening, fraud and risk controls, tax and accounting requirements, payment network rules, disputes, chargebacks, legal claims, and regulatory reporting.
This DPA incorporates by reference Rebill's Privacy Policy, to the extent applicable. If there is a conflict between this DPA and the Privacy Policy with respect to Rebill's Processor obligations, this DPA prevails. If there is a conflict between this DPA and the Service Agreement regarding data protection matters, this DPA prevails; otherwise, the Service Agreement prevails.
2. Scope and Assignment of Roles
2.1 This DPA applies to Rebill's Processing of Merchant Customer Personal Data as Processor in connection with the Processor Services. The details of such Processing are set out in Schedule 1
2.2 The parties agree that Merchant is responsible for determining the purposes and lawful basis for collecting and transmitting Merchant Customer Personal Data to Rebill for the Processor Services.
2.3 Rebill will process Merchant Customer Personal Data as Processor only on Merchant's documented instructions, including the Service Agreement, this DPA, Merchant's configuration of the Services, and Merchant's use of the applicable API, dashboard, or operational workflow, unless Rebill is required to process such Personal Data by applicable law.
2.4 Independent Controller Processing. Notwithstanding anything to the contrary, Rebill acts as an independent Controller where it processes Personal Data to comply with applicable law, financial regulation, AML/KYC obligations, sanctions screening, fraud and risk controls, payment network and card scheme rules, dispute and chargeback management, tax and accounting requirements, security monitoring, regulatory reporting, audits, or legal claims. Such Processing is not performed on Merchant's documented instructions, and Rebill is independently responsible for complying with Applicable Data Protection Law in relation to such Processing.
2.5 No sale of Personal Data. Rebill will not sell Merchant Customer Personal Data or use it for cross-context behavioral advertising or unrelated marketing purposes, except where expressly authorized by Merchant or permitted by Applicable Data Protection Law.
3. Merchant Obligations
3.1 Merchant shall comply with Applicable Data Protection Law in its capacity as Controller, including by providing all required notices and obtaining all required consents or other lawful bases before collecting or transmitting Personal Data to Rebill.
3.2 Merchant shall ensure that its privacy notices disclose the use of Rebill and relevant third parties for payment processing, fraud prevention, risk controls, customer support, regulatory compliance, and other purposes reasonably necessary to provide the Services.
3.3 Merchant shall not instruct Rebill to process Personal Data in a manner that would violate Applicable Data Protection Law, payment network rules, PCI DSS requirements, financial regulation, AML/KYC rules, or the Service Agreement.
3.4 Merchant is responsible for the accuracy, quality, and legality of Personal Data transmitted to Rebill and shall promptly notify Rebill of any material inaccuracy or unauthorized disclosure of Personal Data that may affect the Services.
3.5 Merchant shall not transmit special categories of Personal Data, sensitive Personal Data, or regulated data beyond what is necessary for the Services unless expressly agreed in writing and supported by an applicable lawful basis.
4. Rebill Processor Obligations
4.1 Documented instructions. Rebill shall process Merchant Customer Personal Data as Processor only on documented instructions from Merchant, unless required by applicable law. If Rebill is legally required to process Personal Data outside Merchant's instructions, Rebill shall notify Merchant before such Processing unless legally prohibited.
4.2 Confidentiality and access. Rebill shall ensure that personnel authorized to process Merchant Customer Personal Data are subject to appropriate confidentiality obligations and that access is limited to personnel and systems with a legitimate need to perform the Services.
4.3 Security measures. Rebill shall implement and maintain appropriate technical and organizational measures designed to protect Merchant Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, alteration, or disclosure. Such measures shall include, as applicable, the controls described in Schedule 3.
4.4 PCI and card data. To the extent Rebill processes Cardholder Data, Rebill shall maintain controls designed to comply with applicable PCI DSS requirements for its role. Rebill shall not store card verification codes, CVV, CVC, CID, PINs, or full magnetic stripe data after authorization, even if encrypted, except to the extent expressly permitted by applicable PCI DSS rules.
4.5 Data subject requests. Taking into account the nature of the Processing, Rebill shall provide reasonable assistance to Merchant to respond to requests by Data Subjects exercising rights under Applicable Data Protection Law. If Rebill receives a request directly relating to Merchant Customer Personal Data processed as Processor, Rebill shall, unless legally prohibited, promptly redirect or forward the request to Merchant.
4.6 DPIAs and consultations. Rebill shall provide reasonable assistance to Merchant for data protection impact assessments and prior consultations with supervisory authorities, to the extent required by Applicable Data Protection Law and related to Rebill's Processing as Processor.
4.7 Unlawful instructions. If Rebill reasonably believes that an instruction infringes Applicable Data Protection Law, Rebill shall notify Merchant and may suspend the affected Processing until the parties resolve the issue.
5. Sub-processors
5.1 Merchant grants Rebill general written authorization to engage Sub-processors to provide the Processor Services, subject to the requirements in this Section 5.
5.2 Rebill shall maintain a list of authorized Sub-processors, including name, purpose, processing location, and relevant transfer mechanism where reasonably available. The current list shall be provided in Schedule 2, through a Rebill sub-processor webpage, or upon Merchant's written request.
5.3 Rebill shall impose written data protection obligations on each Sub-processor that are no less protective than those set out in this DPA, to the extent applicable to the nature of the services provided by the Sub-processor.
5.4 Rebill shall provide Merchant with at least thirty (30) days' prior notice before adding or replacing a Sub-processor where required by Applicable Data Protection Law or where the change is material to the Processor Services. Merchant may object on reasonable data protection grounds within fifteen (15) days after notice.
5.5 If the parties cannot resolve a timely and reasonable objection, Merchant may terminate the affected Processor Services without penalty upon thirty (30) days' written notice. This remedy applies only to the affected Processing activities and does not relieve Merchant of payment obligations accrued before termination.
5.6 Rebill remains responsible to Merchant for the acts and omissions of Sub-processors to the same extent Rebill would be responsible if performing the Processor Services directly, subject to the limitations of liability in the Service Agreement and this DPA.
6. Security Incidents and Data Breach Notification
6.1 Rebill shall notify Merchant without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of a Data Breach affecting Merchant Customer Personal Data processed by Rebill as Processor. Rebill may provide an initial notice based on reasonably available information and supplement it as the investigation progresses. A delay in notification that does not materially prejudice Merchant shall not, by itself, constitute a breach of this DPA.
6.2 The notice shall include, to the extent reasonably available: (a) a description of the nature of the Data Breach; (b) categories and approximate number of affected Data Subjects and records; (c) likely consequences; (d) measures taken or proposed to address and mitigate the Data Breach; and (e) contact details for Rebill's security or data protection point of contact.
6.2 The notice shall include, to the extent reasonably available: (a) a description of the nature of the Data Breach; (b) categories and approximate number of affected Data Subjects and records; (c) likely consequences; (d) measures taken or proposed to address and mitigate the Data Breach; and (e) contact details for Rebill's security or data protection point of contact.
6.4 Notification under this Section 6 does not constitute an admission of fault, liability, or violation of law.
7. International Data Transfers
7.1 Merchant Customer Personal Data may be transferred to or processed in countries other than the country where Merchant or Data Subjects are located, including countries where Rebill, its affiliates, acquirers, financial institutions, cloud providers, fraud prevention providers, KYC/AML providers, support platforms, and other Sub-processors operate.
7.2 Where a transfer of Personal Data is subject to cross-border transfer restrictions, Rebill shall ensure that an appropriate transfer mechanism is in place, such as an adequacy decision, standard contractual clauses, binding corporate rules, certification, consent, necessity derogation, or other mechanism recognized under Applicable Data Protection Law.
7.3 For transfers of Personal Data from the European Economic Area, United Kingdom, or Switzerland to a country not recognized as providing adequate protection, the parties shall rely on the applicable standard contractual clauses or equivalent mechanism, as amended or replaced from time to time, and the relevant module shall apply according to the parties' roles.
7.4 For transfers of Personal Data from Brazil subject to the LGPD’s international transfer restrictions, the parties shall apply a transfer mechanism recognized by the ANPD, including the standard contractual clauses approved by the ANPD when required. When such clauses are required, they shall be incorporated in their entirety and without alteration, except for permitted editable fields.
7.5 Upon Merchant's reasonable written request, Rebill shall provide information regarding the transfer mechanisms applicable to the Processor Services, subject to confidentiality, security, and legal restrictions.
8. Audit and Compliance Verification
8.1 Upon reasonable written request, Rebill shall make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of security policies, third-party certifications, attestations, PCI DSS evidence, SOC 2, ISO 27001, penetration test executive summaries, or equivalent materials where available and relevant.
8.2 Merchant may request an on-site or independent audit no more than once per calendar year, and only where the information, reports, certifications, and attestations made available under Section 8.1 are reasonably insufficient to demonstrate compliance, unless an audit is required by a supervisory authority or follows a material Data Breach affecting Merchant Customer Personal Data. Any audit shall be subject to at least thirty (30) days' prior written notice, reasonable scope, confidentiality, security restrictions, and Rebill's policies designed to protect its systems, other customers, and sensitive information.
8.3 The parties shall agree in writing on the scope, timing, duration, and auditor. Rebill may reject an auditor that is a competitor, lacks appropriate qualifications, or presents a conflict of interest, in which case the parties shall cooperate to select an alternative auditor.
8.4 Where Rebill provides a current third-party audit report, certification, or attestation covering the relevant Processing, such materials shall satisfy the audit requirement unless Merchant demonstrates that additional audit activity is legally required or reasonably necessary.
8.5 Audits shall be conducted at Merchant's expense and shall not unreasonably disrupt Rebill's business operations. Audits may not include direct access to production systems, source code, other customers' data, privileged legal advice, or highly sensitive security information.
9. Retention, Return, and Deletion
9.1 Rebill shall retain Merchant Customer Personal Data for the duration of the Service Agreement and for any additional period required or permitted by Applicable Data Protection Law, financial regulation, AML/KYC obligations, tax and accounting rules, card scheme requirements, dispute and chargeback rules, audit requirements, or legal claims.
9.2 Upon termination or expiration of the Service Agreement, and subject to legally required or permitted retention, Rebill shall, at Merchant's written election, return or securely delete Merchant Customer Personal Data processed exclusively as Processor. Rebill shall confirm completion within sixty (60) days after Merchant's written request, unless retention is required or permitted by law.
9.3 Where Rebill retains Personal Data after termination for Independent Controller Processing or legal retention purposes, it shall process such data only for those purposes and maintain appropriate security measures.
9.4 Backups. Personal Data stored in routine backups shall be deleted or overwritten in accordance with Rebill's standard backup lifecycle, provided that such data remains protected and is not restored except as necessary for disaster recovery, security, legal, or compliance purposes.
9.5 Additional retention details are set out in Schedule 4. If Schedule 4 conflicts with mandatory law, the mandatory legal retention period prevails.
10. Liability
10.1 Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Service Agreement, except to the extent prohibited by Applicable Data Protection Law. For the avoidance of doubt, the aggregate liability caps in the Service Agreement and this DPA apply together and not independently, such that the total aggregate liability of either party across both instruments shall not exceed the highest applicable cap set out in the Service Agreement.
10.2 To the extent permitted by applicable law, Rebill’s total aggregate liability to Merchant under or in connection with this DPA shall not exceed fifty percent (50%) of the total fees paid by Merchant to Rebill in the twelve (12) months preceding the event giving rise to the claim.
10.3 The limitations in this Section 10 do not apply to liability arising from a party’s gross negligence or willful misconduct, or to claims that cannot be limited under Applicable Data Protection Law.
11. Term
11.1 This DPA commences on the effective date of the Service Agreement and remains in force for as long as Rebill processes Merchant Customer Personal Data on behalf of Merchant or as otherwise required by Applicable Data Protection Law.
11.2 Termination or expiration of this DPA does not affect rights or obligations accrued before termination and does not affect provisions intended to survive, including Sections 7, 8, 9, 10, 12, and 13.
12. Governing Law and Jurisdiction
12.1 This DPA is governed by the laws specified in the Service Agreement. If the Service Agreement does not specify governing law, this DPA is governed by the laws of the Republic of Argentina, without regard to conflict of law principles.
12.2 Any dispute arising out of or in connection with this DPA shall be subject to the dispute resolution forum specified in the Service Agreement. If none is specified, the parties submit to the exclusive jurisdiction of the competent courts of the City of Buenos Aires, Argentina.
13. General Provisions
13.1 Entire agreement. This DPA, together with the Service Agreement and incorporated documents, constitutes the entire agreement between the parties regarding Rebill's Processing of Merchant Customer Personal Data as Processor.
13.2 Amendments. Rebill may amend this DPA upon thirty (30) days' prior written notice where the amendment is required to comply with changes in Applicable Data Protection Law, payment network rules, regulatory obligations, security requirements, or material changes in the Services. For other amendments, the parties' written agreement is required.
13.3 Severability. If any provision of this DPA is invalid or unenforceable, it shall be modified to the minimum extent necessary to make it valid and enforceable, and the remaining provisions shall remain in effect.
13.4 Order of precedence. In case of conflict regarding data protection matters, this DPA prevails over the Service Agreement unless the Service Agreement expressly states that it overrides this DPA. In all other matters, the Service Agreement prevails.
13.5 No third-party beneficiaries. Except where required by Applicable Data Protection Law or incorporated transfer clauses, this DPA does not create rights for third parties.
14. Execution
This DPA is incorporated into and forms an integral part of the Service Agreement between the parties. It may be executed electronically, through incorporation by reference, or by signature below, as permitted by the Service Agreement and applicable law.
Schedule 1. Details of Processing
Schedule 2. Authorized Sub-processors and Transfer Overview
Rebill uses Sub-processors in the categories below to provide the Services. Provider names, processing locations, and transfer mechanisms may vary by country, payment method, and product configuration. Rebill will make the current Sub-processor list available upon written request, through a Rebill sub-processor webpage, or under confidentiality where appropriate.
Schedule 3. Technical and Organizational Measures
Schedule 4. Retention Framework