Legal & trust
Merchant data terms
How OID4Pay and a merchant share responsibility for personal data in the agent-payment flow.
1. Each side is its own controller
In the agent-payment flow OID4Pay and the merchant each decide their own purposes, so each is an independent controller under the GDPR/AVG, responsible for its own lawful basis and compliance. OID4Pay is the controller for the authorisation layer (issuing and verifying mandates, running the protocol, keeping the audit trail). The merchant is the controller for its commerce (selling, fulfilment, the customer relationship). This is not a processor relationship, so a data-processing agreement is not the instrument between us.
2. What is shared at the protocol boundary
Only what the payment needs: the mandate, the verification result, and transaction metadata. Raw card numbers are never shared; Stripe handles card and payment data. The principal is referenced to the merchant pseudonymously.
3. Both sides commit to
- Appropriate security for the shared data (GDPR Art 32).
- Prompt notice to the other party of a breach affecting shared data.
- Purpose limitation and data minimisation: no onward use beyond the stated purpose.
- Handling their own international transfers. OID4Pay discloses Stripe as a recipient (EU-US Data Privacy Framework, with Standard Contractual Clauses).
- Answering the data-subject requests that fall to them.
4. Settlement
The merchant remains the merchant of record and settles through its own Stripe Connect account. OID4Pay is not a bank or a payment institution and holds no customer balances; it retains only its platform fee.
5. Contact
Merchant data questions: legal@oid4pay.com.