Products

Solutions

Pricing

Developers

Company

Data Processing Agreement

On this page
No headings found

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the services agreement between Moment and the Merchant (the "Services Agreement"), to the extent Moment Processes Personal Data on the Merchant's behalf in the course of providing the Services.

Where the Merchant has not executed a signed services agreement with Moment, "Services Agreement" in this DPA instead means Moment's Merchant Terms and Conditions published on Moment's website, which govern the Merchant's use of the Services in that case, and this DPA is incorporated by reference into those Terms and Conditions accordingly.

This DPA applies regardless of the jurisdiction in which the Merchant is onboarded; jurisdiction-specific data protection law references are set out in Schedule 2. Moment may update this DPA from time to time in accordance with Clause 16 (Version History and Notice of Changes); the version history at the end of this DPA records every published version and when it took effect.

1. Precedence

In the event of a conflict between the provisions of this DPA and the Services Agreement, the provisions of this DPA will take precedence in regard to all aspects pertaining to any Processing of Personal Data by the Operator of any Data Subjects for the Responsible Party.

2. Definitions and Interpretation

All capitalised words and phrases not otherwise defined within the body of this DPA shall have the meanings set forth in the Services Agreement.

"Data Protection Law" means the data protection, privacy, and personal information legislation applicable to the Processing of Personal Data under this DPA in the Merchant's jurisdiction, as identified in Schedule 2, together with any other relevant law, statute, declaration, decree, directive, legislative enactment, order, ordinance, regulation, rule, or other binding instrument which relates to data protection, privacy, or the use of personal information, in each case as applicable and in force from time to time, and as amended, consolidated, re-enacted, or replaced from time to time.

"Data Subject" has the meaning set forth in the applicable Data Protection Law.

"Licensed Partner" means a locally licensed, authorised, or registered partner through which Moment provides the Services in a jurisdiction where Moment does not itself hold the relevant licence, authorisation, or registration, as further described in Clause 12.

"Operator" means an entity which Processes Personal Data on behalf of a Responsible Party. Moment acts as Operator under this DPA.

"Party" or "Parties" means either the Responsible Party or the Operator or both, as the context may require.

"Personal Data" means any information that identifies a Data Subject, or otherwise has the meaning set forth in the applicable Data Protection Law.

"Processing" means any operation or activity or any set of operations, whether or not by automatic means, concerning Personal Data, including: (a) the collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation or use; (b) dissemination by means of transmission, distribution or making available in any other form; or (c) merging, linking, as well as restriction, degradation, erasure or destruction of Personal Data.

"Responsible Party" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes ("why") and means ("how") of the Processing of Personal Data. The Merchant is the Responsible Party under this DPA.

"Security Compromise" means an incident where there has been, or there are reasonable grounds to believe that, Personal Data has been accessed or acquired by an unauthorised person.

"Services Agreement" means the services agreement entered into between the Merchant and Moment to which this DPA is incorporated by reference, or, where the Merchant has not executed such an agreement, Moment's Merchant Terms and Conditions published on Moment's website, as the context requires.

"Staff" means any employee, independent contractor, agent, consultant, subcontractor, or other representative of either Party.

3. Duration

This DPA shall continue to be of force and effect for as long as the Operator remains in possession of any Personal Data of the Data Subjects, regardless of any expiration or termination of the Services Agreement.

4. Processing of Personal Data

4.1 With regards to the Processing of Personal Data pursuant to and for purposes of the Services Agreement, the Merchant is the Responsible Party and Moment is the Operator. The details of the Processing of Personal Data are set forth in Schedule 1.

4.2 It is recorded that, pursuant to its obligations under this DPA, the Parties will Process Personal Data of Data Subjects in connection with and for the purposes of the provision of the Services.

4.3 The Operator acknowledges and agrees that the Responsible Party retains all right, title, and interest in and to the Personal Data and that the Personal Data shall constitute the Responsible Party's confidential information.

4.4 Unless required by law, the Operator shall Process the Personal Data only: (a) in compliance with this DPA; and (b) for the purposes connected with the provision of the Services or as specifically otherwise instructed or authorised by the Responsible Party in writing.

4.5 The Parties shall treat the Personal Data that comes to its knowledge or into its possession as confidential and shall not disclose it without the prior written consent of the other Party, unless required to do so by law, a regulatory officer, pursuant to a court order, or to a Moment Network Partner solely for the provision of the Services.

4.6 Without limiting any obligations under this DPA, the Parties shall comply with applicable industry or professional rules and regulations in relation to the safeguarding of Personal Data.

5. Security

5.1 The Parties shall secure the integrity and confidentiality of Personal Data by taking appropriate, reasonable technical and organisational measures to prevent: (a) loss of, damage to, or unauthorised destruction of Personal Data; and (b) unlawful access to or processing of Personal Data.

6. Security Compromise

6.1 The Parties agree to: (a) notify the other Party in writing within 24 hours if there has been a Security Compromise; and (b) as soon as is reasonably possible, investigate the Security Compromise and furnish the other Party with (i) a preliminary report within 24 hours from its initial notification setting out the details of the Data Subjects affected by the Security Compromise and the nature and extent of the Security Compromise, including (where possible) details of the identity of the unauthorised person who may have accessed or acquired the Personal Data; and (ii) updates on progress made at resolving the Security Compromise.

6.2 The Parties shall take reasonable steps to mitigate the effects and to minimise any damage resulting from the Security Compromise and assist such other Party in remediating or mitigating any potential damage from the breach, to the extent that such remediation or mitigation is within the Party's control, as well as reasonable steps to prevent a recurrence of such a Security Compromise.

7. Operator Staff

The Operator shall: 7.1 limit the Processing of and access to the Personal Data to those Staff who need to know the Personal Data for the Operator to render the Services; and 7.2 ensure that its Staff will not Process Personal Data except in accordance with the provisions of this DPA, and procure that its Staff are contractually obligated to maintain the security and confidentiality of any Personal Data.

8. Access Requests

8.1 Each Party shall: (a) promptly provide assistance to the other Party to comply with any requests received from Data Subjects for access to, correction of, or complaints made by the Data Subjects relating to their Personal Data; and (b) notify the other Party in writing (i) within 3 Business Days of receipt thereof, of any request for access to or correction of the Personal Data or complaints received by the other Party, and provide full details of such request or complaint; and (ii) of any legally binding request for disclosure of Personal Data or any other notice or communication that relates to the Processing of the Personal Data from any supervisory or governmental body.

9. Separation of Personal Data

The Parties shall Process the Personal Data in relation to the Services separately from Personal Data, data, and property relating to any third party, and may not combine or merge Personal Data with information of another party unless otherwise agreed to in writing by the other Party.

10. Return and Retention of Personal Data

10.1 The Parties may, at any time on written request, require that the other Party immediately return to it any Personal Data and may, in addition, require that the other Party furnish a written statement to the effect that upon such return, it has not retained in its possession or under its control, whether directly or indirectly, any such Personal Data or material.

10.2 Alternatively, the Parties shall, as and when required upon written request by the other Party, destroy all such Personal Data and material and furnish such other Party with written confirmation to the effect that the same has been destroyed, unless the law prohibits such Party from doing so, in which case the Parties agree that it will maintain the confidentiality of the Personal Data.

11. Subcontracting

The Operator may subcontract the performance of any of its obligations under this DPA to a third party without the Responsible Party's prior written consent. In doing so, the Operator will ensure that its contract with the subcontractor imposes the same obligations on the subcontractor as are imposed on the Operator in terms of this DPA insofar as the Processing of Personal Data by the subcontractor is concerned.

12. Provision of Services Through Licensed Partners

12.1 In some jurisdictions, Moment is not itself licensed, authorised, or registered to provide regulated payment services. In those jurisdictions, Moment provides the Services using a Licensed Partner operating under its own regulatory permissions, and the Merchant's Services Agreement is nonetheless entered into with Moment.

12.2 Where a Licensed Partner Processes Personal Data for its own regulatory purposes (including customer due diligence, anti-money laundering or counter-terrorist financing checks, sanctions screening, or safeguarding of funds, as required of it under Applicable Law), the Licensed Partner does so as an independent Responsible Party, and not as Moment's Operator or subcontractor under Clause 11. The Merchant acknowledges that such Processing is additionally governed by the relevant Licensed Partner's own privacy notice and terms.

12.3 Where a Licensed Partner instead Processes Personal Data on Moment's instructions, for purposes other than the Licensed Partner's own regulatory obligations, it does so as Moment's subcontractor under Clause 11 (Subcontracting).

12.4 Schedule 2 identifies, for each jurisdiction in which Moment provides the Services through a Licensed Partner, that arrangement and any jurisdiction-specific Personal Data transfer mechanism applicable to the Services.

13. Cross-Border Data Transfer

13.1 It is hereby recorded and agreed that for either Party to be able to fulfil its obligations in terms of the Services Agreement, it may be necessary for such Party to transfer Personal Data to a third party outside the Merchant's jurisdiction of onboarding (as set out in Schedule 2). Where Schedule 2 identifies a specific transfer mechanism required under the applicable Data Protection Law for transfers from that jurisdiction (such as an international data transfer addendum or standard contractual clauses), the Parties shall rely on and give effect to that mechanism for such transfers.

13.2 In the event of such cross-border transfer, the Parties shall: (a) procure the third party's compliance with all the obligations of this DPA insofar as the Processing of Personal Data by the third party is concerned; (b) take reasonable measures to ensure that the third party is prevented from further transferring Personal Data to other third parties; and (c) ensure that the third party has implemented and taken technical and organisational security measures to safeguard the security of the Personal Data in transit.

14. Transmission of Data

Each Party shall ensure that any and all Personal Data communicated, including, without limitation, any digital communication or any Personal Data stored in digital form, shall be secured against being accessed or read by unauthorised parties, using appropriate security safeguards, having due regard to generally accepted information security practices and procedures which may apply to it generally or be required in terms of specific industry or professional rules and regulations.

15. Warranty and Indemnity

15.1 The Responsible Party warrants that it has obtained all necessary notices and consents, and has a lawful basis in place, to enable lawful sharing or transfer of such Personal Data to the Operator, and hereby indemnifies the Operator in respect of all losses, claims, damages, costs, expenses, fines, and penalties, including any claims from Data Subjects, arising from or in connection with the Responsible Party's breach of the warranty provided in this clause 15.1.

15.2 Any financial caps or limitation of liability set out in the Services Agreement shall not apply to this indemnity.

16. Version History and Notice of Changes

16.1 Moment maintains a version history of this DPA, identifying the version number, effective date, and a summary of each change, as set out at the end of this DPA and published at the DPA URL.

16.2 Moment will give the Merchant at least 14 (fourteen) days prior notice of any material change to this DPA, by email to the email address nominated in an Order Form or dashboard, before that change takes effect. Changes that are not material (for example, formatting, clarificatory, or contact-detail updates) may be made without prior notice, and will still be recorded in the version history.

16.3 The version of this DPA identified as current in the version history is the version in effect at any given time and is the version incorporated into the Services Agreement pursuant to Clause 18.6 thereof. Moment will retain, and make available to the Merchant on request, the version of this DPA that was in effect on any specified historical date.

Schedule 1: Details of the Processing

Data Subjects

The Personal Data Processed concern the following Data Subjects. The Merchant may submit Personal Data when using the Services, the extent of which is determined and controlled by the Merchant in its sole discretion, which may include, but is not limited to, Personal Data relating to the following categories of Data Subjects:

  • Customers, business partners, and vendors of the Merchant;

  • Employees or contact persons of the Merchant's vendors or business partners;

  • Employees, agents, advisors, freelancers of the Merchant.

Purpose of Processing

Moment will Process Personal Data on behalf of the Merchant to the extent necessary to:

  • provide, improve, and develop the Services;

  • take steps to prevent, detect, or prosecute fraud or other offences and/or to comply with Applicable Law; and/or

  • as further instructed by the Merchant in its use of the Services.

Categories of Data

The Personal Data transferred concern the following categories of data:

  • Name

  • Identity number

  • Birth date

  • Mobile number

  • Address

Special Personal Data

Details of the Data Subject's Special Personal Data: N/A

Schedule 2: Jurisdiction-Specific Data Protection Law

Nigeria

Where the Merchant is onboarded under a Nigeria Services Agreement, "Data Protection Law" includes the Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection General Application and Implementation Directive (GAID) 2025, as administered by the Nigeria Data Protection Commission (NDPC), together with any other applicable law described in Clause 2 above.

South Africa

Where the Merchant is onboarded under a South Africa Services Agreement, "Data Protection Law" includes the Protection of Personal Information Act 4 of 2013 (POPIA) and the regulations issued thereunder, as administered by the Information Regulator (South Africa), together with any other applicable law described in Clause 2 above.

Version History

Version

Effective Date

Summary of Changes

1.0

August 14, 2026

Initial publication