Settle legal
Data Processing Addendum
These terms apply where you, as a merchant, are a controller of personal data and Settle processes that data on your behalf. This addendum forms part of the Terms of Service and takes effect automatically when you use the service.
Last updated: September 12, 2026
1. Definitions and roles
“Controller”, “processor”, “data subject”, “personal data”, and “processing” have the meanings given in the EU General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR and Data Protection Act 2018.
For personal data relating to your customers — the people who pay you — you are the controller and Settle is your processor. For personal data relating to your own merchant account, and for security and abuse-prevention records about use of the platform, Settle is an independent controller and its Privacy Policy applies.
2. Subject matter and scope of processing
Subject matter: provision of non-custodial stablecoin payment request, checkout, and reconciliation services.
Duration: for as long as your account is active, plus the retention periods described below.
Nature and purpose: creating and displaying payment requests, detecting and reconciling settlement, sending transactional email, maintaining subscription state, providing dispute messaging, and producing merchant-facing analytics.
Categories of data subject: your customers and prospective customers.
Categories of personal data: email address and name where the customer provides them, wallet address, transaction hash and on-chain payment details, subscription status, dispute message content, and a salted irreversible hash of the visitor IP address together with referrer and user-agent for visit counting.
Special category data: none is requested or required. You must not use the service to process special category data.
3. Our obligations as processor
We will:
- Process personal data only on your documented instructions, which the Terms of Service and your use of the platform constitute, unless required otherwise by law — in which case we will tell you before processing, unless the law prohibits it.
- Ensure that personnel authorised to process personal data are bound by confidentiality obligations.
- Implement appropriate technical and organisational measures as described in our Security Policy.
- Assist you, taking into account the nature of processing, in responding to data subject requests and in meeting your obligations for security, breach notification, and data protection impact assessments.
- Notify you without undue delay after becoming aware of a personal data breach affecting your data.
- Delete or return personal data at the end of the service, subject to legal retention requirements and to the immutable nature of blockchain records.
- Make available the information reasonably necessary to demonstrate compliance with this addendum.
4. Your obligations as controller
You are responsible for the lawfulness of the data you collect through the platform, for providing your customers with the notices and, where required, obtaining the consents that apply to your business, for responding to your customers’ data subject requests, and for configuring the service appropriately — including whether a payment link collects an email address at all. You warrant that your instructions to us will not cause us to breach applicable data protection law.
5. Sub-processors
You give general authorisation for us to engage sub-processors. The current list is published at /legal/subprocessors and is updated before a new sub-processor begins processing. You may object on reasonable data-protection grounds within thirty days of a change by writing to [email protected]; if we cannot offer a reasonable alternative, you may terminate the affected service. We remain liable for our sub-processors’ performance of their data protection obligations.
6. International transfers
Where personal data originating in the EEA, the UK, or Switzerland is transferred to a country without an adequacy decision, the transfer is made under the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and subject to a transfer risk assessment.
7. Blockchain data — an important limitation
Settlement data is written to public blockchain networks that no party controls. Once a transaction is confirmed, its details — including wallet addresses and amounts — are permanent, globally replicated, and cannot be amended or erased by us, by you, or by anyone else.
This has a concrete consequence for data subject rights: a request for erasure or rectification can be satisfied within our systems, but not on the blockchain itself. You should reflect this in the privacy notice you give your customers before they pay. We will support you in explaining it, but we cannot engineer around it.
8. Audit
On reasonable written notice, not more than once in any twelve-month period unless required by a supervisory authority, we will respond to a reasonable audit questionnaire regarding our processing under this addendum. Audits must not compromise the security or confidentiality of other merchants’ data.
9. Retention and deletion
Personal data is retained while your account is active. On termination we delete or anonymise merchant-controlled personal data within ninety days, except where retention is required by law or necessary to resolve a dispute, and except for data already written to public blockchains, which cannot be deleted.
10. Order of precedence and contact
In the event of conflict, this addendum prevails over the Terms of Service in respect of the processing of your customers’ personal data. Questions, and requests for a countersigned copy, go to [email protected].