Data Processing Agreement
This DPA forms part of the agreement between the merchant (“Controller”) and Pine Creative Inc. o/a Thaw Payments (“Processor”) for the processing of personal data.
1. Roles & subject matter
The Controller determines the purposes and means of processing; the Processor processes personal data only on the Controller's documented instructions. Subject matter: recovering failed and at-risk subscription payments on the Controller's behalf.
2. Duration
Processing continues for the term of the service. On termination or disconnection, data is retained for 90 days and then deleted, unless the Controller requests earlier deletion.
3. Nature & purpose of processing
Detecting revenue leaks, generating and sending recovery communications, executing compliant payment retries, attributing recoveries, and billing the Processor's fee.
4. Categories of data subjects & personal data
Data subjects: the Controller's end customers. Personal data: name, email, subscription and plan details, payment status and metadata, and card tokens/metadata (never full card numbers — see §7).
5. Controller obligations
The Controller warrants it has a lawful basis to share end-customer data and to instruct the recovery communications sent on its behalf.
6. Processor obligations
The Processor will: process only on documented instructions; ensure personnel are bound by confidentiality; implement the security measures in §8; assist with data-subject requests; and not sell data or use it to train models.
7. Card data
All cardholder data processing remains with Stripe (PCI DSS Level 1). The Processor never stores or has access to full card numbers.
8. Security measures
Row-level data isolation per merchant; server-only secrets; encryption in transit (TLS) and at rest; least-privilege team roles; and an immutable audit log of all actions.
9. Subprocessors
The Controller authorizes the subprocessors listed on the Trust & Security page (Stripe, Supabase, Vercel, Resend, Anthropic, Google Workspace). The Processor remains liable for their performance and will give notice of changes.
10. Data-subject rights
The Processor will assist the Controller in responding to access, correction, deletion, and objection requests, including honoring end-customer unsubscribes and suppression.
11. Personal data breach
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach and provide information reasonably needed to meet the Controller's notification obligations.
12. Deletion & return
On request or at termination, the Processor will delete or return personal data (Controller's choice), subject to the 90-day retention window and any legal retention requirement.
13. Audits
The Processor will make available information necessary to demonstrate compliance and allow for reasonable audits, including via third-party reports once available (SOC 2).
14. International transfers
Where data is transferred across borders, the parties rely on an appropriate transfer mechanism (e.g. Standard Contractual Clauses) as applicable.
Questions: privacy@thawpayments.com.