1. INTRODUCTION
1.1This Data Processing Agreement ("DPA") supplements the Terms of Business (document reference you (the "Client", the "Controller"). It sets out the terms on which we process personal data on your behalf in connection with the services we provide under the Terms of Business.
1.2This DPA is entered into under Article 28 of the UK General Data Protection Regulation (UK GDPR) and applies to all personal data that you, as controller, transfer to us for processing in connection with the execution and settlement of Transactions.
1.3In this DPA: "Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and any applicable data protection legislation in force from time to time; "Personal Data", "Processing", "Controller", "Processor", "Data Subject" and "Personal Data Breach" have the meanings given in the UK GDPR.
1.4Where we process Personal Data for our own regulatory and compliance purposes (including customer due diligence, sanctions screening and anti-money laundering obligations), we act as an independent controller and not as your processor. That processing is governed by our Privacy Notice (document reference KP-PN-001), not by this DPA.
2. SCOPE OF PROCESSING
2.1The details of the processing we carry out on your behalf are set out in the Annex to this DPA. They include the subject matter, duration, nature and purpose of processing, the types of Personal Data and the categories of Data Subjects.
2.2We process Personal Data on your behalf only to the extent necessary to execute and settle Transactions you instruct under the Terms of Business, and for no other purpose unless required by law.
3. OUR OBLIGATIONS AS PROCESSOR
3.1Instructions. We process Personal Data only on your documented instructions, unless required to do so by applicable law. Your instructions are constituted by the Terms of Business, each Transaction instruction and Confirmation, and any other written instruction you provide. If we are required by law to process Personal Data otherwise than on your instructions, we will inform you before doing so unless the law prohibits this.
3.2Confidentiality. We ensure that all personnel authorised to process Personal Data on your behalf are subject to obligations of confidentiality, whether contractual or statutory.
3.3Security. We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in our Privacy Notice and in accordance with Article 32 of the UK GDPR. These measures include access controls, multi-factor authentication, encryption in transit, secure cloud-based storage and regular security reviews.
3.4Sub-processors. You provide general written authorisation for us to engage sub-processors to carry out processing activities on your behalf. We maintain a list of current sub-processors, which is available on request. We will notify you of any intended addition or replacement of a sub-processor at least fourteen (14) days before the change takes effect. If you object to a new sub-processor on reasonable data protection grounds, you may notify us within that period and we will discuss the objection in good faith. If we cannot resolve the objection, you may terminate the affected services without penalty. We impose data protection obligations on each sub-processor by contract that are no less protective than those in this DPA.
3.5Data subject rights. Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures in fulfilling your obligations to respond to Data Subject requests under Data Protection Law. If we receive a request directly from a Data Subject in connection with your Personal Data, we will promptly notify you and will not respond to the request without your instructions, unless required by law.
3.6Breach notification. We notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on your behalf. The notification will include the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach. We will cooperate with you in investigating and remediating the breach and in fulfilling any notification obligations to supervisory authorities or Data Subjects.
3.7Assistance. We provide reasonable assistance to you with data protection impact assessments and prior consultations with supervisory authorities, to the extent that information is available to us and relevant to the processing we carry out on your behalf.
3.8Deletion and return. On termination of the services or on your written request, we will, at your choice, delete or return all Personal Data processed on your behalf and delete existing copies, unless we are required by law to retain the data. Where legal retention obligations apply (including under anti-money laundering regulations), we will inform you and retain only the data required, for the period required, and will securely delete it at the end of that period.
3.9Audit. We make available to you all information necessary to demonstrate compliance with our obligations under this DPA and Article 28 of the UK GDPR. We allow for and contribute to audits and inspections conducted by you or an auditor you appoint, subject to reasonable advance notice, confidentiality obligations and our reasonable security policies. You may exercise this right no more than once per twelve-month period, unless a Personal Data Breach or supervisory authority investigation requires an additional audit.
4. YOUR OBLIGATIONS AS CONTROLLER
4.1You warrant that you have a lawful basis under Data Protection Law for the transfer of Personal Data to us and for our processing of it in accordance with this DPA and the Terms of Business.
4.2You are responsible for ensuring the accuracy and completeness of the Personal Data you provide to us, including Beneficiary details and any personal data of your directors, employees, beneficial owners and authorised users.
4.3You are responsible for providing appropriate notices to Data Subjects whose Personal Data you transfer to us, informing them that their data will be processed by Keystones in accordance with our Privacy Notice.
4.4You will promptly inform us of any Data Subject request, complaint or communication from a supervisory authority that relates to Personal Data processed under this DPA.
5. INTERNATIONAL TRANSFERS
5.1You acknowledge that the provision of our services may require the transfer of Personal Data to countries outside the United Kingdom, including the United States, Cameroon, Côte d’Ivoire and other jurisdictions where Keystones group entities, banking partners or sub-processors operate.
5.2Where we transfer Personal Data outside the United Kingdom on your behalf, we ensure that appropriate safeguards are in place, including: transfers to countries with an adequacy decision; the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses; or other safeguards recognised under Data Protection Law. We carry out transfer impact assessments where required and implement supplementary measures where necessary.
5.3Details of the safeguards in place for international transfers are available on request.
6. LIABILITY
6.1Each party’s liability under this DPA is subject to the limitations and exclusions set out in Section 15 of the Terms of Business.
6.2Nothing in this DPA limits or excludes either party’s liability for breaches of Data Protection Law to the extent that such liability cannot be lawfully limited or excluded.
7. TERM AND GENERAL PROVISIONS
7.1This DPA takes effect on the date of the Terms of Business and continues for so long as we process Personal Data on your behalf.
7.2In the event of any conflict between this DPA and the Terms of Business, this DPA prevails to the extent of the conflict in relation to the processing of Personal Data, as reflected in clause 1.5 of the Terms of Business.
7.3This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the English courts.
7.4We may update this DPA from time to time to reflect changes in Data Protection Law or our processing practices. We will notify you of material changes at least thirty (30) days before they take effect. ANNEX: DETAILS OF PROCESSING This Annex describes the processing of Personal Data carried out by Keystones on behalf of the Client under this DPA. Subject matter Cross-border payment facilitation and spot foreign exchange services as described in the Terms of Business. Duration For the duration of the Terms of Business and for such additional period as is necessary to complete any pending Transactions and satisfy legal retention obligations. Nature and purpose Processing of Personal Data to execute and settle Transactions instructed by the Client, including: receiving and validating payment instructions; transmitting Beneficiary details to banking and payment partners; facilitating the transfer of funds; issuing Confirmations; and maintaining transaction records. Types of Personal Data Beneficiary names; Beneficiary bank account details (account numbers, IBAN, SWIFT/BIC); Beneficiary addresses; transaction amounts, currencies and dates; payment references; and any other personal data included in payment instructions by the Client. Categories of Data Subjects Beneficiaries of Transactions instructed by the Client (including suppliers, service providers, employees, shareholders and other payees designated by the Client). Processing carried out by Keystones as an independent controller (including customer due diligence, identity verification, sanctions screening and regulatory reporting) is outside the scope of this Annex and is governed by the Privacy Notice (KP-PN-001).
