Data Privacy Agreement

Last updateJune 8, 2026

Data Processing Addendum

This Data Processing Addendum (the “DPA”) is incorporated into and forms part of the Managed Payment Facilitation Platform and Integration Agreement (“Agreement”) and is entered into by and between DBD Ventures, LLC d/b/a Forward (“Forward”) and the entity signing the Agreement (“Partner”). This DPA is effective as of the Agreement effective date.

Forward will provide the Forward Services as described in the Agreement (the “Services”) which will involve the Processing of Personal Data. In delivering the Services under the Agreement, to the extent that Forward acts as a data Processor or Subprocessor to Process Personal Data controlled by Partner or Partner’s merchants, this DPA shall apply.

1.  Definitions

All capitalized terms used in this DPA but not otherwise defined herein shall have the meaning ascribed to them in the Agreement.

1.1  “Applicable Data Protection Law(s)” means all data protection and privacy laws and regulations applicable to the Personal Data in question, including, if and where applicable, the EU/UK GDPR and US State Privacy Laws, together with all implementing regulations.

1.2  “Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purpose and means of Processing of Personal Data, as may be further defined under Applicable Data Protection Laws. For the avoidance of doubt, the term “Controller” includes a “business” as defined under the CCPA.

1.3  “Controller to Processor Clauses” means with respect to transfers of Personal Data subject to the EU GDPR, the EU SCCs for the transfer of Personal Data to Third Countries, specifically Module 2 (Controller to Processor).

1.4  “Data Breach” means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

1.5  “Data Subject” means an identified or identifiable individual about whom Personal Data is Processed pursuant to the Agreement. For the avoidance of doubt, the term “Data Subject” includes any “consumer” as that term is defined under the CCPA.

1.6  “EU/UK GDPR” means, as applicable: (i) the General Data Protection Regulation 2016/679 (the “EU GDPR”); (ii) the UK General Data Protection Regulation as defined by the UK Data Protection Act 2018, as amended (the “UK GDPR”); and (iii) any relevant law, directive, order, rule, regulation or other binding instrument which implements any of the above, in each case, as applicable and in force from time to time, and as amended, consolidated, re-enacted or replaced from time to time.

1.7  “Personal Data” means any information provided by Partner or on Partner’s behalf to Forward pursuant to the Agreement that relates to a Data Subject and/or information that is deemed personal data, personal information, or personally identifiable information under Applicable Data Protection Laws.

1.8  “Process” means any operation or set of operations which is performed on Personal Data, whether or not by automated means, such as the access, collection, use, storage, disclosure, dissemination, combination, recording, organization, structuring, adaption, alteration, copying, transfer, retrieval, consultation, disposal, restriction, erasure and/or destruction of Personal Data.

1.9  “Processor” means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of a Controller. For the avoidance of doubt, the term “Processor” includes a “service provider” as defined under the CCPA.

1.10  “Processor to Processor Clauses” means with respect to transfers of Personal Data subject to the EU GDPR, the EU SCCs for the transfer of Personal Data to Third Countries, specifically Module 3 (Processor to Processor).

1.11  “Standard Contractual Clauses or SCCs” means (a) with respect to transfers of Personal Data from the European Economic Area (“EEA”), the standard contractual clauses annexed to the European Commission’s Implementing Decision (EU) 2021/914 of 4 June 2021, as may be amended, superseded, or replaced from time to time (the “EU SCCs”); and (b) with respect to transfers of Personal Data from the United Kingdom (“UK”), the International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses, as issued by the UK Information Commissioner’s Office, as may be amended, superseded, or replaced from time to time (“UK Addendum”).

1.12  “Subprocessor” means any third party engaged directly by Processor to Process any Personal Data in relation to this DPA.

1.13  “Third Country” means any country or territory outside of the scope of the data protection laws of the EEA or the UK, as relevant, excluding countries or territories approved as providing adequate protection for Personal Data by the relevant competent authority from time to time.

1.14  “US State Privacy Laws” means, as applicable, the California Consumer Privacy Act (“CCPA”), Colorado Privacy Act, Connecticut Data Privacy Act, Utah Consumer Privacy Act, the Virginia Consumer Data Protection Act, any similar law of any other state related to the Processing of Personal Data, and any regulations promulgated under any of the foregoing, in each case, as applicable and in force from time to time, and as amended, consolidated, or replaced from time to time.

2.  Role and Purpose of Processing

2.1  Forward’s Processing of Personal Data.

Partner is a Controller of Personal Data and Forward may Process Personal Data as a Processor (or Subprocessor to the extent Partner is acting as a Processor of Personal Data) acting on behalf of Partner in connection with the Services provided under the Agreement, as further described in Annex I, which is incorporated herein by reference. Forward shall Process Personal Data solely for the purposes described herein, as reasonably necessary for the performance of the Agreement, and in accordance with Partner’s documented instructions, except where otherwise required by Applicable Data Protection Laws.

3.  Processor Obligations

3.1  Compliance with Law.

Forward shall Process Personal Data in compliance with Applicable Data Protection Laws and the terms of this DPA. Forward shall promptly notify Partner if, in Forward’s reasonable opinion, an instruction from Partner infringes Applicable Data Protection Laws.

3.2  Confidentiality.

Forward shall ensure that personnel authorized to Process Personal Data have committed to appropriate obligations of confidentiality, whether by contract or by operation of law.

3.3  Security.

Forward shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against Data Breaches, as described further in Annex II to this DPA. Partner acknowledges that such security measures are subject to technical progress and development, and that Forward may update or modify such measures from time to time, provided that such updates or modifications do not materially diminish the overall level of protection afforded to Personal Data.

3.4  Assistance with Data Subject Requests.

Taking into account the nature of the Processing, Forward shall provide reasonable assistance to Partner to enable Partner to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws, including but not limited to rights of access, rectification, erasure, restriction, portability, and objection. If Forward receives a request directly from a Data Subject, Forward shall promptly redirect the Data Subject to Partner, unless otherwise required by Applicable Data Protection Laws.

3.5  Assistance with Compliance Obligations.

Taking into account the nature of the Processing and the information available to Forward, Forward shall provide reasonable assistance to Partner in performing data protection impact assessments and cybersecurity audits.

3.6  Demonstration of Compliance.

Forward shall make available to Partner, upon reasonable request, all information reasonably necessary to demonstrate compliance with the obligations set forth in this DPA and Applicable Data Protection Laws. Upon reasonable notice from Partner and no more than once every 12 months, Forward grants Partner the right to take reasonable and appropriate steps to ensure Forward is using the Personal Data in a manner consistent with Partner’s obligations under Applicable Data Protection Laws.

4.  Subprocessing

4.1  General Authorization.

Partner hereby grants Forward a general written authorization to engage Subprocessors to Process Personal Data on behalf of Partner in connection with the Agreement. Forward shall maintain a list of its current Subprocessors (the “Subprocessor List”), which shall be made available to Partner through a mechanism designated by Forward (such as a webpage or other written notification).

4.2  Notification of Changes.

Forward shall notify Partner of any intended addition or replacement of Subprocessors by updating the Subprocessor List and providing Partner with reasonable advance notice (which shall be no less than fourteen (14) calendar days prior to the engagement of any new or replacement Subprocessor).

4.3  Objection.

Partner may object to Forward’s appointment of a new or replacement Subprocessor on reasonable grounds relating to the protection of Personal Data by notifying Forward in writing within fourteen (14) calendar days of receiving notice of the proposed change. If Partner raises such an objection, the parties shall discuss Partner’s concerns in good faith with a view to achieving a commercially reasonable resolution. If no resolution can be reached within a reasonable period, Partner may, as its sole and exclusive remedy, terminate the Agreement by providing written notice to Forward.

4.4  Subprocessor Obligations.

Forward shall impose data protection obligations on each Subprocessor that are no less protective than those set forth in this DPA by way of a written agreement. Forward shall remain liable to Partner for the acts and omissions of its Subprocessors to the same extent Forward would be liable if performing the Processing directly, subject to the limitations of liability set forth in the Agreement.

5.  Data Breach Notification

Forward shall notify Partner without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a confirmed Data Breach affecting Personal Data Processed under this DPA, and shall reasonably assist Partner in meeting its obligations in response to the Data Breach.

6.  International Data Transfers

6.1  To the extent Forward Processes Personal Data subject to EU/UK GDPR in a Third Country, and Forward is acting as a data importer, Forward shall comply with the data importer’s obligations set out in the Controller to Processor Clauses or, as applicable, the Processor to Processor Clauses, which are hereby incorporated into and form part of this DPA, and:

6.1.1  for the purposes of Annex I or Part 1 of the SCCs (as relevant), (i) Partner is a Controller or Processor (as applicable) and Forward is a Processor or Subprocessor (as applicable), and (ii) the parties, contact person’s details and processing details set out in the Agreement, this DPA and Annex I shall apply and the Start Date is the effective date of the Agreement;

6.1.2  if applicable, for the purposes of Part 1 of the UK Addendum, the relevant Addendum EU SCCs are the EU SCCs as incorporated into this DPA by virtue of this Section 6;

6.1.3  for the purposes of Annex II or Part 1 of the SCCs (as relevant), the technical and organizational security measures set out in Annex II of this DPA shall apply;

6.1.4  if applicable, for the purposes of Annex III or Part 1 of the SCCs (as relevant), the list of authorized sub-contractors set out in the Subprocessor List shall apply; and

6.1.5  if applicable: (i) Clause 7 of the EU SCCs, the optional docking clause is deemed included; (ii) Clause 9 of the EU SCCs, Option 2 (‘General written authorization’) is deemed selected; (iii) Clause 11(a) of the EU SCCs, the optional wording in relation to independent dispute resolution is deemed included; (iv) the competent supervisory authority shall be the Irish regulator; (v) the governing law and competent courts shall be Irish law and Irish courts, respectively; and (vi) the UK Addendum shall be deemed completed with the information set forth in this DPA and Annex I.

7.  Deletion & Return

Upon termination or expiration of the Agreement, Forward shall, at Partner’s election and written request, either return to Partner or securely delete all Personal Data in its possession or control, except to the extent that Forward is required by applicable law to retain any such Personal Data. Partner shall make its election within thirty (30) days following termination or expiration. If Partner does not provide written instructions within such period, Forward shall be entitled to delete the Personal Data. Forward may retain Personal Data to the extent required by applicable law, provided that Forward shall ensure the confidentiality and security of such retained Personal Data and shall not actively Process it for any other purpose.

8.  California Consumer Privacy Act Obligations

8.1  To the extent that Forward’s Processing of Personal Data is governed by the CCPA in Forward’s role as a “service provider” to Partner, then the following clauses shall apply. For purposes of this Section 8, the terms “business,” “consumer,” “sell,” “service provider,” and “share” shall have the meanings ascribed to them under the CCPA.

8.1.1  Forward will not sell or share Personal Data;

8.1.2  Forward will not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in this DPA and the Agreement, or as otherwise permitted under Applicable Data Protection Laws;

8.1.3  Forward will not retain, use, or disclose Personal Data outside of the direct business relationship between Forward and Partner, except as permitted under Applicable Data Protection Laws;

8.1.4  Forward will not combine Personal Data received from or on behalf of Partner with personal information that Forward receives from or on behalf of another person or collects from its own interactions with consumers, except as expressly permitted under Applicable Data Protection Laws; and

8.1.5  Forward will provide the same level of privacy protection as required by Applicable Data Protection Laws.

9.  Liability

Each party’s total aggregate liability under or in connection with this DPA shall be subject to the limitations and exclusions of liability set forth in the Agreement. For the avoidance of doubt, Forward’s total aggregate liability for all claims arising under or in connection with this DPA shall not exceed the limitation of liability set forth in the Agreement. Nothing in this Section shall limit or exclude any liability that cannot be limited or excluded under Applicable Data Protection Laws.

10.  General

10.1  Order of Precedence.

In the event of any conflict or inconsistency between this DPA and the Agreement, this DPA shall prevail to the extent of the conflict with respect to the Processing of Personal Data. In the event of any conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.

10.2  Term.

This DPA shall commence on the effective date of the Agreement and shall remain in force until the Agreement terminates or expires, and thereafter until all Personal Data has been returned or deleted in accordance with Section 7.

10.3  Amendments.

This DPA may be amended only by a written instrument signed by both parties. Notwithstanding the foregoing, Forward may update this DPA from time to time to the extent reasonably necessary to comply with changes in Applicable Data Protection Laws, provided that any such update does not materially diminish the protections afforded to Personal Data under this DPA.

10.4  Severability.

If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect, and the invalid or unenforceable provision shall be modified to the minimum extent necessary to make it valid and enforceable.

10.5  Governing Law.

This DPA shall be governed by and construed in accordance with the governing law provisions of the Agreement, except to the extent that Applicable Data Protection Laws require otherwise (including with respect to the Standard Contractual Clauses, which shall be governed by the law specified therein).

Sub-Processor List

Last updated: June 5, 2026

To support the delivery of our Services, we engage the following sub-processors and service providers to assist with data processing activities on behalf of our customers. Sub-processors are third parties who have, or may have, access to personal data that we process on behalf of our customers.

What is a Sub-processor?

When we engage third-party service providers in our capacity as a data processor, applicable privacy frameworks (including the GDPR) refer to these parties as sub-processors. Sub-processors are service providers who have or potentially will have access to, or process, personal data that we process on behalf of our customers.

This page identifies the sub-processors and service providers we utilize, their location, and a description of the work they carry out.

Due Diligence

Before engaging any sub-processor or service provider, we conduct due diligence including a vendor security assessment. Our sub-processors are subject to contractual terms requiring that they process personal data only for the purposes of providing services to us and in accordance with our commitments to customers and applicable data protection laws.

List of Sub-processors

NAME DATA SHARED PURPOSE OF PROCESSING ENTITY COUNTRY
Amazon Web Services, Inc. All cardholder, merchant, and applicant data at rest and in transit (databases, object storage, secrets, keys) Cloud infrastructure and hosting United States
Fiserv, Inc. Sub-merchant onboarding and underwriting application data (legal name, EIN, beneficial owners, address, MCC); monthly settlement files Merchant boarding, underwriting, and settlement (acquiring processor) United States
CardConnect (a Fiserv company) Cardholder data (card number context, name on card, AVS/CVV results, EMV) Card payment gateway United States
Cross River Bank Bank account and ACH data, payout and settlement transactions, account numbers Banking and ACH rails United States
Plaid Inc. End-user and merchant bank account linking (account and routing data via Plaid tokens) Bank account verification and funding United States
Socure Inc. Applicant KYC data (name, address, email, phone, device signals, watchlist and fraud scores) Individual identity verification (KYC) United States
Baselayer Business KYB data (business name, TIN/EIN, officer names, address, watchlist) Business identity verification (KYB) United States
Taktile The complete merchant/payee onboarding application, including all applicant PII and KYB data Underwriting decisioning engine (orchestrates KYC/KYB vendor calls) United States
Snowflake Inc. Settlement, authorization, funding, and dispute transaction data Data warehouse and settlement analytics United States
Twilio Inc. (SendGrid) End-user and merchant email addresses and message content Transactional email delivery United States
Freshworks Inc. (Freshdesk) Support ticket contents and requester contact details Customer support ticketing United States
Svix Outbound webhook event payloads delivered to partners (payment event data) Webhook delivery infrastructure United States
Very Good Security, Inc. (VGS) Cardholder data (PAN/CVC), network token provisioning, account updater Cardholder data tokenization vault United States
GrailPay Merchant bank account and ACH payment data Bank payment and ACH processing United States
TrueBiz Business application data (reached via Taktile) Business verification United States
Experian plc Applicant identity and credit signal data (via Taktile) Identity and credit data United States
Mastercard MATCH Terminated-merchant screening data (via Taktile) Merchant screening United States
PlanetScale, Inc. Operational transaction and account data Managed database United States
Confluent, Inc. / WarpStream Transaction event-stream data Event streaming infrastructure United States

Updates to this Page

Our business needs and service providers may change from time to time. We will periodically update this page to reflect additions and removals to our list of sub-processors. If you are a customer, you may object in writing to the processing of your personal data by a new sub-processor within 30 days following the update of this page.

If you have questions about our sub-processors or data processing practices, please contact us.

Build payments 
into your product

Want to learn more or apply this specifically to your business? Speak to a payments expert today.

clouds fill