Paradraw
Stripe/Stripe Service Providers, Sub-Processors & Affiliates is drafted as if it could incorporate Data Processing Agreement
Stripe Service Providers, Sub-Processors & Affiliates · p128
notice

Stripe Service Providers, Sub-Processors & Affiliates

2,864 words, 129 clausesupdated September 27, 2026read 08/10/2026source

·Last updated: September 27, 2026

·To support Stripe in delivering its Services, Stripe engages service providers, Sub-Processors and affiliates to assist Stripe with its data processing activities on behalf of Stripe Business Users as defined in our Stripe Services Agreement.

·Summary of Changes

·We've updated this page because we strive to be clear about our use of Personal Data and the third party service providers we engage. The below outlines a few highlights of the changes we made, so please review this page carefully. If you have questions or queries, please contact us.

·You will see that in our List of Affiliates we have:

  • ·removed all references to Stripe, Inc., as this entity no longer exists
  • ·removed Stripe Payments Europe, Limited - Italian Branch, and added our new Italian Affiliate, Stripe Italy S.r.l.
  • ·added Metronome Technologies, Inc., a company Stripe acquired
  • ·updated the name of LemonSqueezy, LLC to its new name Sold Through Link, LLC
  • ·added Microsoft Corporation and Snowflake, Inc. as cloud service providers
  • ·added a new dedicated section for Data Pipeline and added five Cloud service providers for Stripe Data Pipeline: Amazon Web Services, Inc., Databricks, Inc., Google LLC, Microsoft Corporation, and Snowflake Inc.
  • ·updated the purpose of processing description for Adish Co., Ltd. by removing "in Japanese"
  • ·moved Inscribe AI, Inc. from the Identity subsection to the general list of Sub-processors since we also use this party for other Capital and Financial Connections
  • ·added a new subsection for Consumer Issuing and added two Sub-processors to this category: LoanPro Software, LLC and January Technologies, Inc.
  • ·removed Mitek Systems, Inc.
  • ·added direct links to acquired Affiliate's own sub-processors list for Bridge, TaxJar, and Privy
  • ·updated the list of Service Providers for Terminal with new fulfillment and distribution partners

·What is a Sub-processor?

·When Stripe engages third party service providers in our capacity as a data processor for our Business Users' personal data, the General Data Protection Regulation ("GDPR") and a number of other global privacy frameworks call these third-party service providers sub-processors. Sub-processors are service providers who have or potentially will have access to or process personal data that Stripe processes for, and on behalf of, Stripe's Business Users.

·This page outlines the types of service providers, Sub-processors, and affiliates we utilize, where they are located, and a description of the work they carry out.

·Due Diligence

·Before engaging any service provider (including Sub-processors), we perform due diligence, including a vendor security assessment. Our service providers are subject to contract terms designed to ensure that these service providers process personal data only for the purposes of providing services to Stripe and in accordance with our commitments to Business Users and applicable data protection laws.

·List of Sub-processors

NAMEDATAPURPOSE OF PROCESSINGENTITY COUNTRY
Amazon Web Services, Inc.Business User and Representative data and End Customer dataCloud service providerUnited States
Amazon Internet Services Private LimitedBusiness User data and Representative Data. Furthermore, in order to meet regulatory data localization requirements for Indian payment transactions, Stripe India Private Limited stores certain data on servers located in IndiaCloud service providerIndia
Microsoft Corporation (Microsoft Azure)Business User and Representative data and End Customer dataCloud Service ProviderUnited States
Snowflake, Inc.Business User data and End Customer data.Cloud Service ProviderUnited States
Sprinklr, Inc.Information included in the query as provided by the requesterTool to help manage incoming queries via social mediaUnited States
Salesforce, Inc.The information included by the individual reaching out to Stripe, such as name, email address, phone number, and other information that may be included based on the nature of the communicationCustomer service platform that supports customer interactions e.g. emailUnited States
Twilio, Inc.Business User data & End Customer dataCloud communications platform as a service including two factor authentication and user supportUnited States
Intuition Machines, Inc.Business User data & End Customer dataTool that provides hCaptcha for fraud preventionUnited States
Verifi, Inc.Business User data & End Customer dataTool that helps resolve and reduce transaction disputesUnited States
Jack Henry & Associates, Inc.Business User data & End Customer dataPaper check scanning and verification for electronic clearanceUnited States
InscribeAI, Inc.End Customer dataidentity verification for End Customers of Business UsersUnited States User Support
TELUS International (Cda)Information included in the queries raised by the individuals contacting Stripe supportProvide Business User support in several languages and timezonesIreland
AML RightsourceInformation included in the queries raised by the individuals contacting Stripe supportProvide Business User support in several languages and timezonesUnited States
Teleperformance Colombia S.A.S.Information included in the queries raised by the individuals contacting Stripe supportProvide Business User support in several languages and timezonesColombia
TDCX (MY) SDN. BHD.Information included in the queries raised by the individuals contacting Stripe supportProvide Business User support in several languages and timezonesMalaysia
Cognizant Worldwide LimitedInformation included in the queries raised by the individuals contacting Stripe supportProvide Business User support in several languages and timezonesPhilippines, India
WNS Global Services (UK) International LimitedInformation included in the queries raised by the individuals contacting Stripe supportProvide Business User support in several languages and timezonesUnited Kingdom, India
Microsoft CorporationInformation included in the queries raised by the individuals contacting Stripe supportProvide AI technology to improve the quality of user support operationsUnited States
FrontApp, Inc.Information included in the queries raised by the individuals contacting Stripe supportCustomer service tool that supports customer interactions e.g. emailUnited States
Adish Co., Ltd.Information included in the queries raised by the individuals contacting Stripe supportProvide Business User supportJapan
End Customer Credit Card Services.
LoanProSoftware, LLCEnd Customer data of customers and applicants for a credit card for personal use through a Business User.Loan management servicesUnited States
January Technologies, Inc.End Customer data of customers and applicants for a credit card for personal use through a Business User.Manages collections relating to credit cardsUnited States Stripe Identity
Trulioo Information Services, Inc.End Customer dataIdentity verification for End Customers of Business UsersCanada
London Stock Exchange Group plcEnd Customer dataIdentity verification for End Customers of Business UsersUnited States
Data Zoo Pty LimitedEnd Customer dataIdentity verification for End Customers of Business UsersAustralia
Shufti Pro LimitedEnd Customer dataIdentity verification for End Customers of Business UsersUnited Kingdom
LexisNexis Risk Solutions FL, Inc.End Customer dataIdentity verification for End Customers of Business UsersUnited States
Ekata, Inc.End Customer dataIdentity verification for End Customers of Business UsersUnited States
Lob.com, Inc.End Customer dataIdentity verification for End Customers of Business UsersUnited States Data Pipeline
Amazon Web Services, Inc.Business User data and End Customer dataCloud service provider for Stripe Data PipelineUnited States
Databricks, Inc.Business User data and End Customer dataCloud service provider for Stripe Data PipelineUnited States
Google LLCBusiness User data and End Customer dataCloud service provider for Stripe Data PipelineUnited States
Microsoft CorporationBusiness User data and End Customer dataCloud service provider for Stripe Data PipelineUnited States
Snowflake Inc.Business User data and End Customer dataCloud service provider for Stripe Data PipelineUnited States Stripe Atlas
LegalInc.com, Inc.Stripe Atlas Representatives' personal data as required for incorporation in the State of DelawareFile incorporation documents in the State of DelawareUnited States Terminal
FreedomPay, Inc.Business User data & End Customer dataPayment gateway services providerUnited States
Payment method integration service providers
PPRO Payment Services S.A.End Customer and Business User dataPayment method integration service providerLuxembourg
Payla Services GmbHEnd Customer and Business User dataPayment method integration service providerGermany
NETSTARS Co., Ltd.End Customer and Business User dataPayment method integration service providerJapan

·List of Service Providers

·The below list of service providers are some key third parties Stripe works with across our products and services. You will also find some service providers that Stripe works with for a specific Stripe product or service.

NAMEDATAPURPOSE OF PROCESSINGENTITY COUNTRY
DocuSign, Inc.Business User dataeSignaturesUnited States
Google, LLCBusiness User data, End Customers' data and Visitors' dataEmail, file storage, collaboration tools, and services to help protect our Sites (e.g. ReCAPTCHA) and to measure interactions on our SitesUnited States
Marketo, Inc.Business User dataMarketing toolUnited States
Salesforce.com, Inc.Business User dataCustomer relationship management platform which stores Business User contact information as well as supporting information about the business relationshipUnited States
Zoom Video Communications, Inc.Business User data, insofar as that is shared in spoken word between the conversing partiesVideo conferencing systemUnited States
Ekata, Inc.Business User dataProvide sanctions screening servicesUnited States
LegitScript, LLCBusiness User dataProvide merchant monitoring servicesUnited States
User and Sales support service providersInformation included in the queries raised by the individuals contacting Stripe supportProvide user and sales support in several languages and timezonesVarious
Verification service providersBusiness User data and End Customer dataHelp verify the identity of Stripe Business Users and End Customers, and mitigate fraudVarious Stripe Issuing
Idemia America Corp.Cardholder name, PAN, CVV, expiration date, shipping addressPrinting the cards for Stripe IssuingUnited States Stripe Terminal
Various fulfillment and distribution partners, such as Rush Order, Inc., VeriFone, Inc., POS Portal, Inc./ScanSource, Inc., Flexport, Inc., Federal Express Corporation, POSDATA Group, Inc., Technology Recovery Group Ltd., TRG Poland Sp. z o.o., and UKPR Terminal Services LimitedBusiness User name and address for shipping purposesTo enable hardware ordered from Stripe to be shipped to Business Users and to enable warranty claims and repairs for those hardwareVarious

·List of Affiliates

·Other Stripe Entities Involved in Offering the Services

·Stripe may need to rely on Stripe affiliates to help provide the Services to our Business Users, their Customers and our End Users. Stripe affiliates are other entities delivering elements of the Services to our Business Users and End Users. The Stripe affiliates involved in the processing of personal data will depend on the location of our Business Users, their End Customers and our End User, and the nature of the services Stripe is providing.

NameRegionEntity CountryPurpose of Processing
Stripe Payments Canada, Ltd.AMERCanadaPlease see https://stripe.com/en-ca/ssa
Stripe Brokering, Inc.AMERUnited StatesProvide lending facilitation services to bank partners in connection with Stripe Capital loans in the United States
Stripe, LLCAMERUnited StatesPlease see https://stripe.com/ssa
Stripe Payments CompanyAMERUnited StatesPlease see https://stripe.com/ssa and https://stripe.com/legal/spc
Stripe Servicing, Inc.AMERUnited StatesProvide credit collection services related to Stripe Capital in the United States
Stripe Global Technology, LLCAMERUnited StatesUX and related services in connection with the stablecoin financial account product
Sold Through Link, LLC (fka Lemon Squeezy, LLC)AMERUnited StatesMerchant of record related services
TPS Unlimited, Inc.(d/b/a TaxJar)AMERUnited StatesTax-filing related services. See here for TaxJar's own sub-processor list.
Horkos, Inc. (d/b/a Privy)AMERUnited StatesCrypto and stablecoin related services. See here for Privy's own sub-processor list.
Bridge Ventures, LLCAMERUnited StatesCrypto and stablecoin related services. See here for Bridge's own sub-processor list.
Metronome Technologies, Inc.AMERUnited StatesUsage-based billing and metering related services
Stripe Payments Australia Pty Ltd A.C.N. 160 180 343APACAustraliaPlease see https://stripe.com/au/ssa
Stripe India Private LimitedAPACIndiaPlease see https://stripe.com/en-in/ssaIn order to meet regulatory data localization requirements for Indian payment transactions, Stripe India Private Limited stores certain data on servers located in India.
Stripe Technology India Private LimitedAPACIndiaProvides user support as well as internal operational support to other Stripe Affiliates
PT Stripe Payments IndonesiaAPACIndonesiaPlease see https://stripe.com/id/ssa
Stripe Japan, Inc.APACJapanPlease see https://stripe.com/en-jp/legal
Stripe Payments Malaysia Sdn. Bhd.APACMalaysiaPlease see https://stripe.com/en-my/ssa
Stripe New Zealand LimitedAPACNew ZealandPlease see https://stripe.com/nz/ssa
Stripe Payments Singapore Pte. Ltd.APACSingaporePlease see https://stripe.com/en-sg/legal
Stripe Payments (Thailand) Ltd.APACThailandPlease see https://stripe.com/th/legal/ssa
BBPOS Devices LimitedAPACHong Kong SARProviding customer support services in relation to Stripe Terminal products
Noaliasing SPRLEMEABelgiumProvide local marketing and customer support services within Belgium
Stripe France SARLEMEAFranceProvide local marketing and customer support services within France
Stripe Deutschland GmbHEMEAGermanyProvide local marketing and customer support services within Germany
Stripe Payments Europe LimitedEMEAIrelandPlease see https://stripe.com/ie/ssa and https://stripe.com/ie/legal/dpa.
Stripe Technology Company LimitedEMEAIrelandData controller located in Ireland with primary responsibility for processing Personal Data outside of the Americas. Together with relevant Stripe local regulated entities (those who are licensed, authorized or registered by a Local Regulatory Authority) and Stripe Payments Europe Limited.
Stripe Technology Europe, LimitedEMEAIrelandFor payment services, as an e-money institution regulated by the Central Bank of Ireland.
Stripe Israel Payments Ltd.EMEAIsraelProvide local marketing and customer support services within Israel
Stripe Italy S.r.l.EMEAItalyProvide local marketing and customer support services within Italy
Stripe Netherlands B.V.EMEANetherlandsProvide local marketing and customer support services within the Netherlands
Stripe Payments sp. z o.o.EMEAPolandProvide local marketing and customer support services within Poland
Stripe Spain S.L.EMEASpainProvide local marketing and customer support services within Spain
Tiny Experiment AktiebolagEMEASwedenProvide local marketing and customer support services within Sweden
Stripe Switzerland GmbHEMEASwitzerlandProvide local marketing and customer support services within Switzerland
Stripe Romania S.R.L.EMEARomaniaProvide local marketing and customer support services within Romania
Stripe FZ-LLCEMEAUnited Arab EmiratesProvide local marketing and customer support services within the United Arab Emirates
Stripe Payments UK, Ltd.EMEAUKTogether with Stripe Technology Company Limited and Stripe Payments Europe Limited, the e-money licensed entity with the UK FCA. Please see https://stripe.com/gs/ssa
Bridge Building Sp. Z.o.o.EMEAPolandCrypto and stablecoin related services
Bridge Building S.A.EMEALuxembourgCrypto and stablecoin related services
Stripe Brasil Soluções de Pagamento - Instituição de Pagamento LtdaLATAMBrazilPlease see https://stripe.com/br/ssa
Stripe Payments Mexico, S. de R.L. de C.V.LATAMMexicoPlease see https://stripe.com/en-mx/ssaProvides user support as well as internal operational support to other Stripe Affiliates.

·Updates to this Page

·Due to the nature of our global business and the volume of Business Users, our business needs and services providers may change from time to time. For example, we may deprecate a service provider to consolidate and minimize our use of service providers. Similarly, we may add a service provider if we believe that doing so will enhance our ability to deliver our Services.

·We will periodically update this page to reflect additions and removals to our list of service providers, Sub-processors and Affiliates. If you are a Business User, you may subscribe to receive email notifications of updates to our list of Sub-processors on this page here.

·Under the terms of our Data Processing Agreement (DPA), a Business User may reasonably object in writing to the processing of its personal data by a new Sub-processor within 30 days following the update of this page. If a Business User does not object during the 30 day time period, the appointment of the new Sub-processor shall be deemed accepted by the Business User. If you are a Business User and want to know more about our DPA, please contact us.

·For more information on Stripe's privacy practices, please visit our Privacy Policy. If you have any questions regarding this page, please contact us.

Data Processing Agreement · p1
Part of the agreement

Data Processing Agreement

4,175 words, 106 clausesupdated 28 September 2026read 08/10/2026source

If you would like more information on our Data Processing Agreement, please see our FAQs. Need a copy of this Data Processing Agreement? Click here. Last updated: 28 September 2026

11. Scope.

·This Data Processing Agreement ("DPA") is between the Stripe entity specified in the Agreement (and its Affiliate(s), collectively "Stripe") and the User specified in the Agreement, and is subject to and incorporated by reference into the Agreement. This DPA governs Stripe's and its Affiliates' Processing of Personal Data.

22. Stripe as Data Processor and Data Controller

Data Processing Roles
Stripe as a Data ProcessorWhen Stripe Processes Personal Data as a Data Processor, it is acting as a Data Processor on behalf of User, the Data Controller.
Stripe as a Data ControllerWhen Stripe Processes Personal Data as a Data Controller it: - has the sole and exclusive authority to determine the purposes and means of Processing Personal Data it receives from or through User; and- may engage a Stripe Affiliate to act as (a) a Joint Controller to provide products and services, including Authorised Services; (b) an independent Data Controller to provide Authorised Services; and (c) a Data Processor to provide services other than Authorised Services. Data Processing Purposes
Stripe as a Data ProcessorThe purposes of Stripe's Processing of Personal Data in its capacity as a Data Processor are to:- service the Stripe platform; and- provide, and provide access to, Stripe's products and services.
Stripe as a Data ControllerThe purposes of Stripe's Processing of Personal Data in its capacity as a Data Controller when providing Stripe's products and services are to:- determine and utilise third parties (banks and payment method providers);- monitor, prevent and detect fraudulent transactions and other fraudulent activity on the Stripe platform;- monitor, prevent and mitigate financial loss, security risks and other harm;- implement, maintain and perform internal processes that enable Stripe to provide its products and services, including relationship management, billing and invoicing;- comply with Law, including applicable anti-money laundering screening and know-your-customer obligations, and Financial Provider and Governmental Authority requirements and requests; and- analyse, improve and develop Stripe's products and services.
Categories of Data Subjects and Personal Data: Stripe as a Data Processor and a Data Controller
Data SubjectsStripe may Process the Personal Data of Customers, representatives and any natural person who accesses or uses the Stripe Account.
Personal DataIf applicable, Stripe may Process Payment Method Account Details, bank account details, billing/shipping address, name, order description (including date, time, amount, product or service description), device ID, email address, IP address/location, order ID, payment card details, tax ID/status, unique customer identifier, identity information including government issued documents (e.g., national IDs, driving licences and passports), cryptocurrency wallet address.
Sensitive DataIf applicable, Stripe may Process Sensitive Data (e.g., facial recognition data). Duration of Processing
Stripe as a Data ProcessorFor the Term and any period required to perform a party's post-termination obligations. Data Security
Stripe as a Data Processor and Data ControllerStripe will implement and maintain a written information security programme with the Data Security Measures stated in the Exhibit of this DPA.

33. Stripe Obligations when Acting as a Data Processor.

3.13.1 Obligations.

·When Stripe is acting as a Data Processor for User, Stripe will, to the extent required by DP Law:

·(a) Process Personal Data on User's behalf and according to User's Instructions. Stripe will inform User if, in its opinion, Instructions violate or infringe DP Law;

·(b) ensure that all persons Stripe authorises to Process Personal Data are granted access to Personal Data on a need-to-know basis and are committed to respecting the confidentiality of that Personal Data;

·(c) inform User of each request Stripe receives from Data Subjects (including "verifiable consumer requests" as defined under the CCPA) exercising their rights under DP Law to (i) access (e.g., right to know under the CCPA) their Personal Data; (ii) have their Personal Data corrected or erased; (iii) restrict or object to Stripe's Processing; or (iv) data portability (collectively "Data Subject Request"). Other than to request further information, identify the Data Subject and, if applicable, direct the Data Subject to User as Data Controller, Stripe will not respond to these requests unless User instructs Stripe in writing to do so. Taking into account the nature of the Processing, Stripe will assist User by appropriate technical and organisational measures, insofar as this is possible, to enable User to meet its obligation to respond to a Data Subject Request;

·(d) inform User of each law enforcement request Stripe receives from a Governmental Authority requiring Stripe to disclose Personal Data or participate in an investigation requiring Stripe to disclose Personal Data, unless prohibited by Law;

·(e) provide User with reasonable assistance, following User's written request, to help User comply with its obligations under DP Law and, taking into account the nature of the Processing and the information available to Stripe, Stripe will provide reasonable information to help User conduct a data protection impact assessment or consult with a Supervisory Authority. If User requests assistance from Stripe that goes beyond Stripe's obligations under DP Law or this Agreement, Stripe may charge User a reasonable fee;

·(f) if Stripe experiences a Data Incident, notify User without undue delay, which for Data Incidents affecting Personal Data subject to the GDPR or UK GDPR will be no later than 48 hours, in each case after becoming aware of the Data Incident. To the extent known to Stripe, Stripe's notification to User will describe in reasonable detail (i) the type of Personal Data that was the subject of the Data Incident, (ii) the categories and potential number of individuals or records affected (including their countries) and (iii) the status of Stripe's investigation and current or planned remediation. Following the notification, Stripe will provide relevant updates to assist User in complying with its obligations under DP Law;

·(g) following User's written request, contribute to audits or inspections by making audit reports available to User. Following this request, and no more frequently than once annually, Stripe will promptly provide documentation or complete a written data security questionnaire of reasonable scope and duration regarding Stripe's and its Affiliates' Processing of Personal Data. All reports and documentation provided, including any response to a security questionnaire, are Stripe's confidential information; and

·(h) at User's choice, delete or return to User all Personal Data Processed in connection with the Services, and delete existing copies, following termination of the Agreement, except that Stripe will not be required to delete or return that Personal Data, or delete existing copies, to the extent that Stripe's storage of that Personal Data or those copies is (i) required by Stripe to exercise its rights and perform its obligations under this Agreement; or (ii) required or authorised by DP Law for a longer period.

3.23.2 Sub-processors.

·(a) Stripe engages Sub-processors, which may include its Affiliates, as necessary to perform the Services. User consents to Stripe's use of its existing Sub-processors, as set out on the Stripe Sub-processors List, and grants Stripe a general written authorisation to engage Sub-processors as necessary to perform the Services. If User subscribes to email notifications at the Stripe Sub-processors List, then Stripe will notify User via email if Stripe intends to add one or more Sub-processors to that list at least 30 days before the changes take effect. User may reasonably object to a change on legitimate grounds within 30 days after User receives notice of the change. User acknowledges that Stripe's Sub-processors are essential to provide the Services and that if User objects to Stripe's use of a Sub-processor, then notwithstanding anything to the contrary in the Agreement (including this DPA), Stripe will not be obliged to provide User the Services for which Stripe uses that Sub-processor.

·(b) Stripe will enter into a written agreement with each Sub-processor that imposes on that Sub-processor obligations comparable to those imposed on Stripe under this DPA, including the obligation to implement appropriate Data Security Measures. If a Sub-processor fails to fulfil its data protection obligations under that agreement, Stripe will remain liable to User for the acts and omissions of its Sub-processor to the same extent Stripe would be liable if performing the relevant Services directly under this DPA.

3.33.3 United States Specific Data Protection Obligations.

·To the extent that US State DP Law applies and Stripe is acting as a Data Processor, Stripe certifies that it understands and will comply with its obligations under US State Privacy Law to:

·(a) not sell or share (as defined under the CCPA) Personal Data;

·(b) only Process Personal Data for the purposes set out in this DPA, the Agreement or otherwise permitted by Law;

·(c) not retain, use or disclose Personal Data outside of its direct business relationship with User other than to provide Stripe's products and services and as required to comply with Law; and

·(d) not combine Personal Data received from or through User with Personal Data received from or on behalf of an individual or collected from Stripe's own interactions with the individual, unless permitted by US State DP Law or at the individual's direction.

·(e) provide no less than the level of protection to Personal Data as required by US State DP Law; and

·(f) inform User if it determines that it can no longer meet its obligations under the US State DP Law and will grant User the right to take reasonable and appropriate steps to remediate any unauthorised Processing of Personal Data.

3.43.4 Disclaimer of Liability.

·Notwithstanding anything to the contrary in the Agreement, including this DPA, Stripe and its Affiliates will not be liable for any claim made by a Data Subject arising from or related to Stripe's or any of its Affiliates' acts or omissions, to the extent that Stripe was acting in accordance with User's Instructions.

44. User's obligations when acting as a Data Controller.

4.14.1 Instructions.

·User must only provide Instructions to Stripe that are lawful;

4.24.2 Compliance with DP Law.

·User must comply with and perform User's obligations under DP Law, including with regard to Data Subject rights, data security and confidentiality and ensure User has an appropriate legal basis for the Processing of Personal Data as described in the Agreement, including this DPA; and

4.34.3 Disclosures.

·User must provide all necessary notices (including by making available a Privacy Policy) to, and obtain all necessary rights, permissions and consents from, Data Subjects (including Customers), to enable Stripe to lawfully Process any Personal Data provided by User as described in the Agreement, including this DPA. User is solely responsible for the content of notices it provides to its Customers.

55. Stripe's obligations when acting as a Data Controller.

·Stripe must comply with and perform its obligations under DP Law when Processing Personal Data, including making available a Privacy Policy that explains how and for what purposes Stripe collects, uses, retains, discloses and safeguards Personal Data.

66. Data transfers.

6.16.1 Cross-border Data Transfers by User.

·User acknowledges that in order for Stripe to provide the Services, User transfers Personal Data to Stripe, LLC in the United States. If the transfer comprises Personal Data that requires a Data Transfer Mechanism, the Data Transfers Addendum, which is incorporated into this DPA, will apply.

6.26.2 Cross-border Data Transfers by Stripe.

·Stripe and its Affiliates may transfer Personal Data on a global basis as necessary to provide the Services. In particular, Personal Data may be transferred to Stripe, LLC in the United States and to Stripe's Affiliates and Sub-processors in other jurisdictions.

77. Conflict.

·To the extent of any conflict between the provisions of this DPA and any provision of the:

·(a) Agreement regarding Personal Data Processing, the provisions of this DPA will prevail; and

·(b) Data Transfers Addendum, the provisions of the Data Transfers Addendum will prevail.

88. Definitions.

·Capitalised terms not defined in this DPA have the meanings given to them in the Agreement.

·"Agreement" has the meaning given in the Stripe services agreement between User and Stripe located at www.stripe.com/legal/ssa, or as otherwise agreed by the parties.

·"Authorised Services" means Services that a Governmental Authority licenses, authorises or regulates.

·"CCPA" means California Consumer Privacy Act of 2018, Cal. Civ. Code Sections 1798.100-1798.199, and its implementing regulations.

·"Data Controller" means the entity which, alone or jointly with others, determines the purposes and means of Processing Personal Data, which may include, as applicable, a "Business" as defined under the CCPA.

·"Data Incident" means an unauthorised or unlawful Processing, use, access, loss, disclosure, destruction or alteration of Personal Data in a party's or its Affiliate's, or a party's or its Affiliate's subcontractor's, agent's or representative's, possession or control.

·"Data Privacy Framework" means, as applicable, the EU-US, Swiss-US or UK-US Data Privacy Framework self-certification programme operated by the US Department of Commerce.

·"Data Processor" means the entity that Processes Personal Data on behalf of the Data Controller, which may include, as applicable, a "Service Provider" as defined under the CCPA.

·"Data Security Measures" means technical and organisational measures that are intended to secure Personal Data to a level of security appropriate for the risk of the Processing.

·"data subject" means an identified or identifiable natural person to which Personal Data relates.

·"Data transfer Mechanism" means a transfer mechanism that enables the lawful cross-border transfer of Personal Data under DP Law, which includes transfer mechanisms that are required under DP Law in the EEA, Switzerland and the UK, such as the Data Privacy Framework, the EEA SCCs, the UK International Data Transfer Addendum and any data transfer mechanism available under DP Law that is incorporated into this DPA.

·"Data Transfers Addendum" means the data transfers addendum located at www.stripe.com/legal/dta, as updated from time to time.

·"DP Law" means Law that applies to Personal Data Processing under the Agreement and this DPA, including international, federal, state, provincial and local Law relating in any way to privacy, Data protection or data security.

·"EEA" means the European Economic Area (EEA).

·"EEA SCCs" means Module 1 (Transfer: Controller to Controller), Module 2 (Transfer: Controller to Processor) and, as applicable, Module 3 (Transfer: Processor to Processor) of the standard contractual clauses set out in the European Commission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries according to the GDPR.

·"GDPR" means General Data Protection Regulation (EU) 2016/679.

·"Instructions" means any communication or documentation, including that which may be provided through a Stripe API, or Stripe Dashboard, or written agreements between User and Stripe through which the Data Controller instructs a Data Processor to perform specific Processing of Personal Data for that Data Controller.

·"Joint Controller" means a Data Controller that jointly determines the purposes and means of Processing Personal Data with one or more Data Controllers.

·"Personal Data" means any information relating to an identifiable natural person that is Processed in connection with the Services, and includes "personal data" as defined under the GDPR and "personal information" as defined under the CCPA.

·"Privacy Policy" means any or all of a publicly posted Privacy Policy, privacy notice, data policy, cookies policy, cookies notice or other similar public policy or public notice that addresses a party's Personal Data practices and commitments.

·"Process" means to perform any operation or set of operations on Personal Data or sets of Personal Data, such as collecting, recording, organising, structuring, storing, adapting or altering, retrieving, consulting, using, disclosing by transmission, disseminating or otherwise making available, aligning or combining, restricting, erasing or destroying, as described under DP Law. "Processed" and "Processing" have corresponding meanings.

·"Sensitive Data" means, to the extent this data is treated distinctly as a special category of Personal Data under DP Law: (a) Personal Data that is genetic data, biometric data, data concerning health, a natural person's sex life or sexual orientation; (b) data about racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership; (c) geolocation data; or (d) sensitive personal information as defined under the CCPA.

·"sub-processor" means an entity a Data Processor engages to Process Personal Data on that Data Processor's behalf in connection with the Services.

·"Stripe Sub-processors List" means the list of Stripe's Sub-processors and Affiliates located at www. stripe.com/legal/service-providers, as updated from time to time.

·"Supervisory Authority" means an independent public authority which is (i) established by a European Union member state pursuant to Article 51 of the GDPR; or (ii) the public authority governing data protection that has supervisory authority and jurisdiction over User.

·"UK GDPR" means the GDPR, as transposed into United Kingdom national law by operation of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019.

·"UK International Data Transfer Addendum" means the international data transfer addendum to the EEA SCCs issued by the United Kingdom's Information Commissioner's Office.

·"US State DP Law" means DP Law applicable in the United States, which may include, among others, the CCPA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act and the Utah Consumer Privacy Act.

ExhibitEXHIBIT: STRIPE DATA SECURITY

Security Programs and PoliciesStripe maintains and enforces a security program that addresses how Stripe manages security, including its security controls. The security program includes: - documented policies that Stripe formally approves, internally publishes, communicates to appropriate personnel and reviews at least annually; - documented, clear assignment of responsibility and authority for security program activities; - policies covering, as applicable, acceptable computer use, data classification, cryptographic controls, access control, removable media and remote access; and - regular testing of the key controls, systems and procedures.Privacy Program. Stripe maintains and enforces a privacy program and related policies that address how Personal Data is collected, used and shared.
Risk and Asset ManagementStripe performs risk assessments, and implements and maintains controls for risk identification, analysis, monitoring, reporting and corrective action.Stripe maintains and enforces an asset management program that appropriately classifies and controls hardware and software assets throughout their life cycle.
Personnel Education and ControlsAll (a) Stripe employees; and (b) Stripe independent contractors who may have access to data, including those who Process Personal Data ((a) and (b), collectively ''Personnel") acknowledge their data security and privacy responsibilities under Stripe's policies.For Personnel, Stripe, either itself or through a third party: - implements pre-employment background checks and screening; - conducts security and privacy training; - implements disciplinary processes for violations of data security or privacy requirements; and - upon termination or applicable role change, promptly removes or updates Personnel access rights and requires Personnel to return or destroy Personal Data.Authentication. Stripe authenticates each Personnel's identity through appropriate authentication credentials such as strong passwords, token devices or biometrics.
Training and AwarenessAnnual Security and Privacy Training. Stripe's employees complete an annual Security and Privacy awareness training on Stripe's data security and confidentiality policies and practices.
Network and Operations ManagementPolicies and Procedures. Stripe implements policies and procedures for network and operations management. These policies and procedures address hardening, change control, segregation of duties, separation of development and production environments, technical architecture management, network security, malware protection, protection of data in transit and at rest, data integrity, encryption, audit logs and network segregation.Vulnerability Assessments. Stripe performs periodic vulnerability assessments and penetration testing on its systems and applications, including those that Process Personal Data. Vulnerabilities are managed and remediated in accordance with Stripe's Vulnerability Management Standard.
Technical Access ControlsAccess control. Stripe implements measures to prevent data processing systems from being used by unauthorised persons, including the following measures:- user identification and authentication procedures; - ID/password security procedures, including stronger digital authentication measures based on NIST 800-63B including MFA;- automatic blocking (e.g., password or timeout); and- break-in-attempt monitoring. Data access control. Stripe implements measures to ensure that persons entitled to use a data processing system gain access only to the Personal Data allowed for their access rights, and that Personal Data cannot be read, copied, modified or deleted without authorisation, including:- internal policies and procedures;- control authorisation schemes;- differentiated access rights (profiles, roles, actions and objects);- access monitoring and logging;- access reports;- access procedure;- change procedure; and- deletion procedure.
Physical access controlsStripe uses reputable third-party service providers to host its production infrastructure. Stripe relies on these third parties to manage the physical access controls to the data centre facilities that they manage. Some of the measures that Stripe's service providers provide to prevent unauthorised persons from gaining physical access to the data processing systems available at premises and facilities (including databases, application servers and related hardware), where Personal Data is Processed, include:- physical access control system and program in place at Stripe premises;- 24x7 Global Security Operation Center that monitors physical security systems;- security video and alarm systems;- access control roles and area zones;- access control audit measures;- electronic tracking and management program for keys;- access authorisations process for employees and third parties;- door locking (electrified locks etc.); and- trained uniformed security staff.Stripe reviews third-party audit reports to verify that Stripe's service providers maintain appropriate physical access controls for the managed data centres.
Availability ControlsStripe implements measures to ensure the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident, including:- database replication;- backup procedures;- hardware redundancy; and- a disaster recovery plan.
Disclosure ControlsStripe implements measures to ensure that Personal Data (a) cannot be read, copied, modified or deleted without authorisation during electronic transmission, transport or storage on storage media (manual or electronic); and (b) can be verified to which companies or other legal entities Personal Data are disclosed, including logging, transport security and encryption.
Entry ControlsStripe implements measures to monitor whether data have been entered, changed or removed (deleted) and by whom, from data processing systems, including logging and reporting systems and audit trails and documentation.
Separation ControlsStripe implements measures to ensure that Personal Data collected for different purposes can be Processed separately, including:- "least privilege" limitation of access to data by internal services;- segregation of functions (production/testing);- procedures for storage, amendment, deletion, transmission of data for different purposes; and- logical segmentation processes to manage the separation of Personal Data.
Certifications and ReportsPCI Compliance. To the extent applicable to the Services, Stripe is responsible for providing the Services in a manner that is consistent with the highest certification level (PCI Level 1) provided by the PCI-DSS requirements. Stripe's certification is confirmed annually by a qualified security assessor (QSA).SOC Reports. Stripe maintains Service Organisation Controls ("SOC") auditing standards for service organisations issued under the AICPA. SOC 1 and 2 reports are produced annually and will be provided upon request. Stripe may add standards or certifications at any time.
EncryptionStripe applies data encryption mechanisms at multiple points in Stripe's service to mitigate the risk of unauthorised access to Stripe data at rest and in transit. Access to Stripe cryptographic key materials is restricted to a limited number of authorised Personnel.Encryption in transit. To protect data in transit, Stripe requires all inbound and outbound data connections to be encrypted using cryptographic protocols, cipher suites and key exchange mechanisms approved under current NIST guidelines. For data traversing Stripe's internal production networks, Stripe uses mutual authentication and encryption (mTLS) to secure connections between production systems.Encryption at rest. To protect data at rest, Stripe encrypts all production data stored in server infrastructure using encryption algorithms and key lengths that meet or exceed NIST recommendations for symmetric encryption.Payment Card and Banking Account Data Tokenisation. Payment card and bank numbers are stored in a separate, highly restricted data vault and are separately encrypted at the data level using NIST-approved symmetric encryption algorithms and key lengths. Decryption keys are stored on separate machines. Tokens are generated to support Stripe data processing.
Reviews, Audit Reports and Security QuestionnairesUpon written request, and no more frequently than annually, Stripe will complete a written data security questionnaire of reasonable scope and duration regarding Stripe's business practices and data technology environment in relation to the Processing of Personal Data. Stripe's responses to the security questionnaire are Stripe's confidential data.
System ConfigurationStripe implements measures for ensuring system configuration, including default configuration measures for internal IT and IT security governance.Stripe relies on deployment automation tools to deploy infrastructure and system configuration. These automation tools leverage infrastructure configurations that are managed through code that flows through Stripe's change control processes. Stripe's change management processes require formal code reviews and two-party approvals prior to the release to production.Stripe uses monitoring tools to monitor production infrastructure for changes from known configuration baselines.
Data PortabilityThe Stripe API enables Users to programmatically access the data stored for transfer, excluding PCI-scoped data. The portability process for PCI data to other PCI-DSS Level 1 compliant payment processors can be found at https://stripe.com/docs/security/data-migrations/exports.
Data Retention and DeletionStripe implements and maintains data retention policies and procedures related to Personal Data and reviews these policies and procedures as appropriate.

·Download the DPA

·Click here to download the Stripe DPA