This Data Processing Agreement (DPA) is a clear and legally binding document between us, Rayocorp Amaze, acting as the “Data Processor,” and you, our user, acting as the “Data Controller.” Its purpose is to explain how we process and safeguard your personal data when you use our payment services.
When we refer to “we,” “our,” or “us,” we mean Rayocorp Amaze. When we say “you” or “your,” we are referring to you. By using our services, you agree to the terms described in this agreement, ensuring that your data is handled responsibly and with appropriate care.
Within this arrangement, you, as the Controller, determine the reasons and methods for processing data and are responsible for complying with all applicable data protection laws. We, as the Processor, process your personal data strictly according to your instructions and solely for the purpose of delivering our payment services. This clear separation of roles supports accountability and mutual trust.
We process your information only for purposes that ensure your transactions remain secure, compliant, and efficient. Your data is used for:
To initiate, authorize, and settle transactions.
To confirm your identity and prevent fraudulent activities.
To apply security protections such as two-factor authentication.
To generate accurate transaction histories and reports.
To meet all applicable requirements from RBI and payment networks.
We place strong importance on the protection of your data. To safeguard it, we implement robust technical and organizational controls, including:
We follow industry standards for managing cardholder data.
Strong encryption is used to protect information both during transmission and while stored.
Multi-factor authentication is applied to secure access to systems.
We conduct vulnerability assessments and penetration testing to identify and address potential risks.
All members of our staff receive training in data protection and are required to maintain strict confidentiality.
We are dedicated to supporting your ability to maintain control over your personal information. We will assist in addressing requests from individuals regarding their data rights, including:
The right to view the personal data we hold about you.
The ability to update or correct inaccurate or incomplete information.
The right to request deletion of your personal data when appropriate.
The option to obtain your information in a transferable format.
The right to limit or object to the processing of your data.
We will not engage any third party to process your data without your prior written consent. When Subprocessors are used, they are bound by written agreements that require them to follow data protection standards equal to or stronger than our own. This ensures that your information remains protected at all times, regardless of who is involved in the processing.
In the unlikely event that a data breach occurs, we will notify you immediately and always within 24 hours. The notification will include details about the incident, the number of individuals affected, and the measures being taken to contain the breach and prevent similar events in the future. This commitment ensures prompt and transparent communication.
To maintain transparency and confidence, you have the right to audit our compliance with this agreement. With reasonable prior notice, you may review our records, policies, and certifications, including our security compliance reports. We will provide access to the necessary documentation to confirm that we are fulfilling our obligations.
We retain your personal data only for as long as necessary to process payments and meet legal obligations, including those required by the RBI. Once services conclude, we will securely delete or return all personal data unless legal requirements require us to retain it for a longer period.
Regulatory frameworks may evolve over time. If new legal or regulatory developments affect how personal data must be handled, we will inform you promptly. This ensures that both parties remain aware of any changes that may impact compliance.
If either party fails to fulfill their responsibilities under this agreement, they will be responsible for any resulting damages. We will also indemnify you against any fines or losses arising from our failure to meet our data protection obligations.
This agreement will be governed and interpreted in accordance with the laws of India. Any disputes arising from this agreement will be handled exclusively in the courts located in India, ensuring a consistent and predictable legal process for both parties.
Any modifications to this agreement must be documented in writing and signed by both parties to become valid. This ensures that all changes are clearly recorded and mutually agreed upon.
By entering into this agreement, both parties confirm that they have read, understood, and accepted all of the terms outlined above. This reflects a shared commitment to transparency, accountability, and protecting the data entrusted to us.