Data Processing Addendum
Last Updated: September 11, 2026
This Data Processing Addendum (“DPA”) forms part of the Coinsnap Terms of Service (“Terms”) between the Merchant and Onlineshop24 DOO, operating under the Coinsnap brand (“Coinsnap”).
1. Purpose and Applicability
This DPA applies only to the extent that Coinsnap processes Personal Data on behalf of a Merchant in connection with the Coinsnap Services.
In particular, this DPA may apply where a Merchant chooses to provide Coinsnap with Personal Data relating to its customers or Payers for functionality such as:
- transaction attribution;
- order or invoice reconciliation;
- Merchant Dashboard functionality;
- reporting;
- accounting exports;
- APIs and webhooks;
- integrations with Merchant systems; or
- technical transmission to a Third-Party Provider selected by the Merchant.
This DPA does not apply to processing activities for which Coinsnap independently determines the purposes and means of processing and therefore acts as an independent Controller.
Such processing may include, for example:
- Merchant account administration;
- contract administration;
- billing and tax administration;
- account security;
- login and access logging;
- customer support;
- service-related communications;
- Coinsnap’s own legal compliance; and
- operation and security of Coinsnap’s own systems.
Further information concerning Coinsnap’s different data protection roles is provided in the Coinsnap Privacy Policy.
2. Incorporation into the Coinsnap Agreement
This DPA is incorporated into and forms part of the Coinsnap Terms of Service.
By accepting the Terms, the Merchant also accepts this DPA to the extent that it applies to the Merchant’s use of Coinsnap.
No separate signature, countersignature or individually negotiated data processing agreement is required unless mandatory Applicable Data Protection Law requires otherwise.
Coinsnap does not generally enter into individually negotiated data processing agreements for its standard Merchant Services.
The DPA applies automatically only to processing for which Coinsnap acts as a Processor on behalf of the Merchant.
If there is a conflict between this DPA and another provision of the Terms concerning processing for which Coinsnap acts as a Processor, this DPA prevails with respect to that processing.
3. Definitions
For the purposes of this DPA:
“Applicable Data Protection Law” means data protection or privacy law applicable to the particular processing activity covered by this DPA.
“Controller” means the person or entity that determines the purposes and means of processing Personal Data, or the equivalent role under Applicable Data Protection Law.
“Merchant” means the Coinsnap customer that has accepted the Terms.
“Merchant Personal Data” means Personal Data processed by Coinsnap on behalf of the Merchant under this DPA.
“Merchant-Provided Payer Data” means Personal Data relating to a customer or Payer that the Merchant intentionally provides to Coinsnap.
“Personal Data” means information relating to an identified or identifiable natural person, or equivalent information protected under Applicable Data Protection Law.
“Payer” means a person making or intending to make a Bitcoin payment to a Merchant.
“Process” or “Processing” has the meaning given to that term under Applicable Data Protection Law.
“Processor” means a person or entity processing Personal Data on behalf of a Controller, or the equivalent role under Applicable Data Protection Law.
“Subprocessor” means another Processor engaged by Coinsnap to process Merchant Personal Data on behalf of the Merchant.
“Third-Party Provider” means an independent provider selected or used by a Merchant to provide its own service, including financial, conversion, brokerage, banking or settlement services.
4. Roles of the Parties
To the extent that this DPA applies:
the Merchant acts as Controller; and
Coinsnap acts as Processor on behalf of the Merchant.
The Merchant determines:
- whether Personal Data relating to its customers or Payers is collected;
- why that information is collected;
- whether it is associated with a Bitcoin payment;
- whether it is transmitted to Coinsnap;
- which Coinsnap functionality is used; and
- whether information is transmitted to another system or Third-Party Provider.
Coinsnap processes Merchant Personal Data only to provide the functionality selected by the Merchant and in accordance with the Merchant’s documented instructions.
The Merchant’s configuration and use of the Coinsnap Services constitute documented instructions for purposes of this DPA.
5. Standard Bitcoin Payments
Coinsnap does not require identification of a Payer merely in order to detect a standard self-custodial Bitcoin or Lightning payment.
For standard payment functionality, Coinsnap primarily processes technical transaction information such as:
- invoice or order identifiers;
- payment amounts;
- Bitcoin addresses;
- Lightning payment information;
- transaction identifiers;
- payment hashes;
- timestamps; and
- payment status.
Such information is covered by this DPA only to the extent that it constitutes Personal Data and Coinsnap processes it on behalf of the Merchant.
Coinsnap does not store the Payer’s IP address as part of the standard Bitcoin or Lightning payment transaction record.
Coinsnap’s role in processing Personal Data does not change the underlying Bitcoin payment flow. For a standard self-custodial Coinsnap payment, Bitcoin is transferred directly from the Payer through the Bitcoin or Lightning Network to the wallet destination selected by the Merchant.
Coinsnap does not receive, hold or take possession of the Bitcoin at any stage of the standard self-custodial payment flow.
6. Merchant Instructions
Coinsnap will process Merchant Personal Data only:
- on documented instructions from the Merchant;
- as necessary to provide the Coinsnap functionality selected by the Merchant;
- as required to comply with applicable law; or
- as otherwise expressly agreed between Coinsnap and the Merchant.
The Merchant’s documented instructions include instructions resulting from:
- account configuration;
- Merchant Dashboard actions;
- API requests;
- plugin configuration;
- webhook configuration;
- integrations selected by the Merchant; and
- other documented communications with Coinsnap.
Where Coinsnap is legally required to process Merchant Personal Data other than on the Merchant’s instructions, Coinsnap will inform the Merchant of that requirement before processing unless applicable law prohibits such notification.
Coinsnap will inform the Merchant if Coinsnap reasonably believes that an instruction infringes Applicable Data Protection Law.
7. Merchant Responsibilities
The Merchant is responsible for ensuring that:
- it has a lawful basis for processing Merchant Personal Data;
- affected individuals receive any information required under Applicable Data Protection Law;
- Personal Data submitted to Coinsnap is adequate, relevant and limited to what is necessary;
- Coinsnap’s processing instructions are lawful;
- the Merchant has the necessary rights to provide the data to Coinsnap; and
- the Merchant’s use of Coinsnap complies with laws applicable to the Merchant and its customers.
The Merchant should not submit Personal Data to Coinsnap unless it is necessary for functionality selected by the Merchant.
Where a non-personal order, invoice or customer reference can reasonably be used instead, Merchants are encouraged to avoid unnecessary Personal Data.
The Merchant remains responsible for its own relationship with its customers and Payers, including its privacy notices and other information required under Applicable Data Protection Law.
8. Confidentiality
Coinsnap will ensure that persons authorised to process Merchant Personal Data are subject to appropriate confidentiality obligations.
Access to Merchant Personal Data will be limited to persons who require such access for purposes related to the provision, operation, support or security of the Coinsnap Services.
9. Security
Coinsnap will implement and maintain appropriate technical and organisational measures designed to protect Merchant Personal Data against:
- accidental or unlawful destruction;
- accidental loss;
- unauthorised alteration;
- unauthorised disclosure;
- unauthorised access; and
- other unlawful processing.
Measures will be appropriate to the nature of the Processing and the risks presented by the relevant Coinsnap functionality.
The categories of technical and organisational measures applicable to processing covered by this DPA are described in Annex II.
Coinsnap may update its security measures as technologies, services and risks change, provided that the overall level of protection is not materially reduced.
10. Subprocessors
The Merchant grants Coinsnap general authorisation to engage Subprocessors where reasonably necessary to provide, secure, maintain or support the Coinsnap Services.
Coinsnap will require Subprocessors that process Merchant Personal Data on Coinsnap’s behalf to be subject to appropriate contractual data protection obligations consistent with the obligations applicable to Coinsnap under this DPA.
Coinsnap remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law.
Coinsnap maintains an internal record of relevant Subprocessors used in connection with processing covered by this DPA.
Coinsnap does not maintain a publicly accessible Subprocessor list and is not required to publicly disclose confidential information concerning its technical infrastructure, security architecture, commercial arrangements or service-provider relationships except to the extent such disclosure is required by Applicable Data Protection Law.
Upon reasonable request, Coinsnap will provide an affected Merchant with information concerning Subprocessors relevant to that Merchant’s Processing activities where such information is reasonably necessary for the Merchant to fulfil its obligations under Applicable Data Protection Law.
Such information may include, where relevant:
- the identity of the Subprocessor;
- the general purpose of the Processing;
- the categories of Personal Data concerned; and
- the relevant Processing jurisdiction.
Coinsnap may withhold technical, commercial, security-sensitive or other confidential information that is not reasonably necessary for the Merchant to fulfil its obligations under Applicable Data Protection Law.
Where Applicable Data Protection Law requires advance notification of the addition or replacement of a Subprocessor, Coinsnap will provide the affected Merchant with appropriate written or electronic notice before the relevant change takes effect.
Such notice may be provided through:
- email;
- the Coinsnap Merchant account; or
- another appropriate electronic communication channel.
Where legally required, the Merchant will have a reasonable opportunity to object to a new or replacement Subprocessor on legitimate data protection grounds.
An objection must relate to the protection of Personal Data and not solely to a general commercial preference concerning Coinsnap’s choice of service provider.
If Coinsnap and the Merchant cannot reasonably resolve a valid objection, Coinsnap may permit the Merchant to discontinue the affected functionality or, where necessary, terminate the relevant Coinsnap Service.
Independent Third-Party Providers selected by a Merchant and acting for their own purposes are not Subprocessors merely because Coinsnap provides a technical integration with them.
11. Third-Party Financial and Settlement Providers
A Merchant may choose to use an independent Third-Party Provider for services such as:
- Bitcoin-to-fiat conversion;
- brokerage;
- exchange;
- banking; or
- settlement to a bank account.
Such providers may require Personal Data relating to a Merchant or Payer in order to provide their service or comply with their own regulatory obligations.
Where instructed by the Merchant and supported by the relevant integration, Coinsnap may technically transmit Merchant-Provided Payer Data to the selected Third-Party Provider.
Where the Third-Party Provider determines the purposes and means of its own Processing, including Processing for KYC, KYB, AML, sanctions, banking, settlement or regulatory compliance, the Third-Party Provider acts under its own responsibility and is not acting as a Subprocessor of Coinsnap for that independent Processing.
Coinsnap does not independently determine the regulatory data requirements imposed by such Third-Party Providers.
The Third-Party Provider’s own terms, privacy policy and regulatory framework apply to its independent Processing activities.
12. Assistance With Individual Rights
Where Coinsnap processes Merchant Personal Data on behalf of the Merchant, the Merchant remains primarily responsible for responding to requests from its customers or Payers concerning their Personal Data.
Taking into account the nature of the Processing, Coinsnap will provide reasonable assistance to the Merchant where necessary for the Merchant to respond to requests concerning rights available under Applicable Data Protection Law.
If Coinsnap receives a request directly from an individual concerning Merchant Personal Data, Coinsnap may refer that person to the relevant Merchant unless Coinsnap is legally required to respond directly.
Coinsnap will not independently respond to such a request on behalf of the Merchant unless authorised or legally required to do so.
13. Assistance With Compliance Obligations
Taking into account the nature of the Processing and the information available to Coinsnap, Coinsnap will provide reasonable assistance where required under Applicable Data Protection Law concerning:
- security of Processing;
- Personal Data breaches;
- data protection impact assessments; and
- consultations with competent supervisory authorities.
The extent of such assistance will be proportionate to Coinsnap’s role and the relevant Coinsnap functionality.
14. Personal Data Breaches
Coinsnap will notify the Merchant without undue delay after becoming aware of a Personal Data breach affecting Merchant Personal Data where notification is required under Applicable Data Protection Law.
Where reasonably available, the notification will include information concerning:
- the nature of the incident;
- affected data;
- likely consequences;
- measures taken or proposed by Coinsnap; and
- information reasonably required by the Merchant to assess its own notification obligations.
Coinsnap may provide information in stages where not all relevant information is available at the same time.
Coinsnap’s notification of an incident does not constitute an admission of fault or liability.
15. Return and Deletion of Merchant Personal Data
Upon termination of the relevant Coinsnap Service, Coinsnap will delete or return Merchant Personal Data where required by Applicable Data Protection Law and according to the Merchant’s applicable instructions, unless applicable law requires or permits further retention.
Deletion obligations do not apply to information that:
- Coinsnap must retain under applicable law;
- is retained where legally permitted for the establishment, exercise or defence of legal claims;
- has been irreversibly anonymised; or
- is permanently recorded on a public blockchain outside Coinsnap’s control.
Where Merchant Personal Data remains in backup systems, deletion may occur through the normal backup lifecycle, provided that the information remains appropriately protected and is not restored for ordinary operational purposes.
16. Demonstration of Compliance and Audits
Coinsnap will make available information reasonably necessary to demonstrate compliance with Processor obligations applicable to the Processing covered by this DPA.
Where required by Applicable Data Protection Law, Coinsnap will permit and reasonably contribute to audits relating specifically to the Processing of Merchant Personal Data.
The parties agree that, where reasonably sufficient, compliance should first be demonstrated through less intrusive means such as:
- written information;
- security documentation;
- compliance questionnaires;
- policies;
- certifications, where available;
- independent audit reports, where available; or
- other appropriate remote evidence.
An on-site inspection should only be requested where the Merchant cannot reasonably obtain the information required under Applicable Data Protection Law through less intrusive means or where an inspection is otherwise legally required.
Except following a material Personal Data breach, a request from a competent supervisory authority or other circumstances reasonably requiring additional review, Merchant-initiated audits should normally be limited to once in any twelve-month period.
Audits must:
- be conducted on reasonable advance notice;
- occur during normal business hours;
- avoid unreasonable disruption to Coinsnap’s operations;
- protect confidential information concerning other customers;
- protect Coinsnap’s technical and security information; and
- be subject to appropriate confidentiality obligations.
The Merchant will bear its own audit costs and, where permitted by Applicable Data Protection Law, Coinsnap may charge reasonable costs resulting from unusually burdensome or Merchant-specific audit requests.
Nothing in this Section limits mandatory audit rights that cannot lawfully be restricted.
17. International Processing
Coinsnap is operated by Onlineshop24 DOO in Serbia.
Accordingly, Merchant Personal Data submitted to Coinsnap may be processed in Serbia.
Information may also be processed in other jurisdictions where authorised Subprocessors or relevant infrastructure providers operate.
The Merchant is responsible for determining whether its transfer of Personal Data to Coinsnap is subject to international data transfer requirements under the law applicable to the Merchant.
Coinsnap will provide reasonable information concerning relevant Processing locations and safeguards where such information is required under Applicable Data Protection Law.
18. International Transfer Safeguards
Where Applicable Data Protection Law requires a specific safeguard for an international transfer of Merchant Personal Data to Coinsnap, the parties will use an appropriate legally recognised transfer mechanism.
Depending on the Applicable Data Protection Law and circumstances, such mechanism may include:
- standard contractual clauses;
- an adequacy mechanism;
- another statutory transfer mechanism; or
- another legally recognised contractual safeguard.
No particular international transfer mechanism is deemed to apply automatically merely because this DPA applies.
The applicability of a particular mechanism depends on the relevant jurisdictions, the respective roles of the parties and the law applicable to the specific transfer.
19. EEA and GDPR Transfers
Where:
- the Merchant is subject to the GDPR in relation to the relevant Personal Data;
- Merchant Personal Data is transferred to Coinsnap in Serbia;
- the transfer constitutes a transfer subject to Chapter V GDPR; and
- no applicable adequacy decision or other transfer mechanism permits the transfer without additional safeguards,
the parties will use an appropriate legally recognised transfer mechanism where required by Applicable Data Protection Law.
Where the European Commission Standard Contractual Clauses are legally appropriate for the relevant transfer, Coinsnap may make the applicable standardised transfer terms available to the Merchant.
The appropriate transfer mechanism and, where relevant, the applicable SCC module, parties, roles, options, competent supervisory authority, governing terms and annex information will be determined according to the actual circumstances of the relevant transfer.
Coinsnap may provide a standardised electronic mechanism through which an eligible Merchant can accept applicable transfer terms without individually negotiating those terms with Coinsnap.
Activation of such transfer terms may require the Merchant to confirm or provide information necessary to identify the Merchant and complete the relevant contractual information.
Acceptance of this DPA does not by itself mean that EU Standard Contractual Clauses apply to every Merchant, every processing activity or every transfer to Coinsnap.
20. Relationship With EU Standard Contractual Clauses
Where applicable EU Standard Contractual Clauses have been validly incorporated into the contractual relationship for a particular transfer, those clauses form part of the agreement governing that transfer.
Nothing in this DPA is intended to modify the mandatory text of applicable EU Standard Contractual Clauses.
Where an applicable Standard Contractual Clause conflicts with this DPA, the Standard Contractual Clause prevails to the extent of that conflict.
Any required:
- modules;
- options;
- party details;
- supervisory authority information;
- governing law selections;
- annex information; and
- Subprocessor information
will be determined according to the actual roles and circumstances of the relevant transfer.
Where applicable Standard Contractual Clauses require information regarding authorised Subprocessors, Coinsnap will provide such information to the relevant Merchant in accordance with those clauses.
Such information does not need to be published generally or disclosed to persons who are not parties to the relevant Processing relationship unless legally required.
21. Processing for Coinsnap’s Own Purposes
This DPA does not govern Personal Data that Coinsnap processes as an independent Controller.
Such Processing may include:
- Merchant account information;
- Merchant contact information;
- invoices and billing records;
- tax information;
- Merchant registration information;
- Merchant login and security records;
- support communications;
- service-related communications;
- information concerning the contractual relationship with the Merchant;
- security investigations; and
- information required for Coinsnap’s own legal compliance.
Such Processing is governed by the Coinsnap Privacy Policy and Applicable Data Protection Law.
22. Liability
Liability arising under this DPA is subject to the liability provisions contained in the Terms, except to the extent Applicable Data Protection Law or applicable Standard Contractual Clauses require otherwise.
Nothing in this DPA limits liability that cannot lawfully be limited.
23. Duration
This DPA becomes effective when the Merchant accepts the Coinsnap Terms and applies for as long as Coinsnap processes Merchant Personal Data on behalf of that Merchant.
The obligations concerning confidentiality, security, deletion and other provisions that by their nature survive termination will continue for as long as Coinsnap retains relevant Merchant Personal Data.
24. Changes to This DPA
Coinsnap may update this DPA where reasonably necessary to reflect:
- changes in Applicable Data Protection Law;
- changes to data protection requirements;
- changes to Coinsnap Services;
- changes to technical or organisational measures;
- changes to Processing activities; or
- improvements to Coinsnap’s data protection framework.
Coinsnap will not materially reduce the protection of Merchant Personal Data through an update to this DPA during an active Merchant relationship.
Where required by Applicable Data Protection Law or where a change materially affects the Merchant’s data protection rights or obligations, Coinsnap will provide appropriate notice.
Changes concerning Subprocessors are governed by Section 10.
25. Governing Law
Except where mandatory Applicable Data Protection Law or incorporated Standard Contractual Clauses require otherwise, this DPA is governed by the law governing the Coinsnap Terms of Service.
26. Contact
Questions relating to this DPA may be addressed to:
Coinsnap / Onlineshop24 DOO
Ljubimira Ivkovica Suce 75
11453 Sopot (Ducina)
Serbia
Email: support@coinsnap.io
Annex I – Details of Processing
1. Subject Matter
Processing of Merchant Personal Data where necessary to provide Coinsnap software functionality selected by the Merchant.
2. Duration
For the duration of the Merchant’s use of the relevant Coinsnap functionality and any subsequent retention period permitted or required under this DPA, the Terms, Merchant instructions or Applicable Data Protection Law.
3. Nature of Processing
Depending on the functionality selected by the Merchant, Processing may include:
- receiving;
- receiving information from Merchant-controlled systems;
- transmitting;
- storing;
- structuring;
- organising;
- displaying;
- retrieving;
- associating;
- matching;
- exporting;
- reporting;
- deleting; and
- providing technical access through APIs, webhooks or integrations.
4. Purposes of Processing
Purposes may include:
- associating a Bitcoin payment with an order or invoice;
- transaction reconciliation;
- displaying transaction information to the Merchant;
- generating transaction histories;
- generating Merchant reports;
- accounting exports;
- Merchant-selected APIs and webhooks;
- Merchant system integrations; and
- technical transmission to a Third-Party Provider selected by the Merchant.
Coinsnap does not process Merchant Personal Data under this DPA for unrelated consumer advertising or Payer profiling.
5. Categories of Data Subjects
Depending on Merchant use, Data Subjects may include:
- customers of the Merchant;
- Payers;
- prospective customers where information is associated with an initiated transaction; and
- other individuals whose Personal Data the Merchant intentionally submits through supported Coinsnap functionality.
6. Categories of Personal Data
Depending on the functionality selected by the Merchant, Merchant Personal Data may include:
Merchant-Provided Payer Data
- name;
- email address;
- customer reference;
- invoice reference;
- order reference;
- accounting reference;
- delivery or transaction reference; and
- other transaction-related information intentionally supplied by the Merchant.
Technical Payment Data, Where It Constitutes Personal Data
- Bitcoin addresses;
- Lightning payment information;
- transaction identifiers;
- payment hashes;
- transaction amounts;
- timestamps;
- payment status; and
- information associating a transaction with a Merchant order or invoice.
Coinsnap does not require standard Bitcoin payment detection to include the Payer’s name, postal address, email address or identity document.
Coinsnap does not store the Payer’s IP address as part of the standard Bitcoin or Lightning payment transaction record.
7. Special Categories of Personal Data
Coinsnap’s standard Merchant Services are not designed for the Processing of special categories of Personal Data or similarly sensitive information.
Merchants must not intentionally submit such information unless Coinsnap has expressly confirmed that the relevant functionality supports such Processing and the Merchant has an appropriate lawful basis.
8. Frequency
Processing occurs as initiated by the Merchant or its systems when the relevant Coinsnap functionality is used.
9. Merchant Instructions
The Merchant’s documented instructions are determined through:
- its use of Coinsnap;
- account configuration;
- API requests;
- plugin configuration;
- Merchant Dashboard actions;
- integrations selected by the Merchant; and
- other documented communications with Coinsnap.
Annex II – Technical and Organisational Measures
Coinsnap maintains technical and organisational measures appropriate to the nature and risk of the relevant Processing.
The measures described below identify general categories of safeguards and are not intended to disclose confidential details of Coinsnap’s technical infrastructure or security architecture.
Access Control
Measures may include, as appropriate to the relevant Coinsnap system:
- limiting access to production systems according to operational need;
- authentication controls for administrative access;
- restricted access to Merchant information;
- management of User and administrative permissions; and
- account access logging where appropriate.
Communication Security
Measures may include:
- encrypted transport for supported communications between Users and Coinsnap systems;
- secure API communication mechanisms; and
- protection of authentication credentials and API secrets.
Account Security
Measures may include:
- authentication mechanisms;
- Merchant login and security event logging;
- monitoring and investigation of suspicious or unauthorised access; and
- controls intended to protect Merchant accounts against misuse.
Data Minimisation
Coinsnap’s architecture and procedures are intended to minimise unnecessary Personal Data Processing.
In particular:
- standard self-custodial payment detection does not require Payer identification;
- Merchants are encouraged to use non-personal transaction references where possible;
- Payer IP addresses are not stored as part of the standard Bitcoin or Lightning payment transaction record; and
- access to Personal Data is limited according to operational requirements.
Self-Custody Architecture
For the standard Coinsnap Merchant payment model:
- Coinsnap does not need to hold Merchant Bitcoin in order to provide payment detection functionality;
- Merchant private keys are not required for standard payment detection;
- Bitcoin payments are directed to Merchant-selected wallet destinations; and
- Coinsnap does not use custodial control of Merchant Bitcoin as part of its Processing of Merchant Personal Data.
Infrastructure and Availability
Appropriate measures may include:
- infrastructure monitoring;
- software maintenance;
- backup and recovery processes where appropriate;
- dependency and update management; and
- controls intended to maintain system availability and integrity.
Security Incident Handling
Coinsnap maintains procedures intended to:
- identify security incidents;
- assess affected systems and information;
- limit or remediate identified risks;
- document relevant incidents; and
- notify affected Merchants where required.
Personnel and Confidentiality
Persons authorised to access Merchant Personal Data are subject to appropriate confidentiality obligations and access restrictions.
Service Provider Management
Where a Subprocessor processes Merchant Personal Data on behalf of Coinsnap, Coinsnap requires appropriate contractual data protection and security obligations.
Coinsnap reviews and may adapt these measures as systems, technologies and risks develop.
Further confidential technical or security details are not publicly disclosed unless disclosure is required by Applicable Data Protection Law or reasonably necessary to demonstrate compliance to an affected Merchant.
Annex III – Subprocessors
Coinsnap may engage Subprocessors as described in Section 10 of this DPA.
The Merchant grants Coinsnap the general authorisation described in Section 10 to engage and replace Subprocessors where reasonably necessary to operate, secure, maintain or support the Coinsnap Services.
Coinsnap maintains an internal record of Subprocessors that process Merchant Personal Data on behalf of Coinsnap.
Coinsnap does not maintain a publicly accessible list of its Subprocessors and does not publicly disclose confidential information concerning its technical infrastructure, security architecture, commercial arrangements or service-provider relationships except where required by Applicable Data Protection Law.
Upon reasonable request, Coinsnap will provide an affected Merchant with information concerning the Subprocessors relevant to that Merchant’s Processing activities where such information is reasonably necessary for the Merchant to fulfil its obligations under Applicable Data Protection Law.
Depending on the applicable requirements, such information may include:
- the identity of the relevant Subprocessor;
- the general purpose of the Processing;
- the categories of Personal Data concerned; and
- the relevant Processing jurisdiction.
Coinsnap may withhold technical, commercial, security-sensitive or other confidential information that is not reasonably necessary for the Merchant to fulfil its obligations under Applicable Data Protection Law.
Where Applicable Data Protection Law requires advance notification of a new or replacement Subprocessor, Coinsnap will provide such notice in accordance with Section 10.
Independent Third-Party Providers that determine their own purposes and means of Processing are not Subprocessors for such independent Processing.
Where applicable international transfer terms, including EU Standard Contractual Clauses, require additional Subprocessor information to be provided to a particular Merchant, Coinsnap will provide the information required by those terms directly to that Merchant.
Annex IV – International Transfer Information
1. Data Importer
Onlineshop24 DOO / Coinsnap
Ljubimira Ivkovica Suce 75
11453 Sopot (Ducina)
Serbia
Role:
Processor, solely to the extent described in this DPA.
2. Data Exporter
Where applicable, the Data Exporter is the Merchant identified through the relevant Coinsnap Merchant account.
The Merchant’s registered:
- legal or business name;
- business address;
- country;
- account identification; and
- contact information
may be used to identify the Merchant for purposes of an applicable standardised international transfer mechanism.
3. Transfer
The subject matter, nature, purposes, categories of Personal Data and categories of Data Subjects are described in Annex I.
4. Frequency
Transfers may occur on a continuous or recurring basis according to the Merchant’s use of the relevant Coinsnap functionality.
5. Retention
Retention is governed by this DPA, the Coinsnap Privacy Policy, Merchant instructions and Applicable Data Protection Law.
6. Transfer Mechanism
No specific international transfer mechanism is automatically incorporated merely by acceptance of this DPA.
Where Applicable Data Protection Law requires additional contractual safeguards for a particular transfer, the parties will use an appropriate legally recognised transfer mechanism.
Where EU Standard Contractual Clauses are legally appropriate, Coinsnap may make the relevant standardised transfer terms available through an electronic process.
7. Additional Information for International Transfer Terms
Where a particular international transfer mechanism requires additional contractual information, the relevant transfer documentation will identify or determine, as applicable:
- the Data Exporter;
- the Data Importer;
- the roles of the parties;
- the applicable transfer mechanism;
- the applicable SCC module, where relevant;
- any required options;
- the competent supervisory authority, where required;
- governing law and courts, where required;
- relevant Subprocessor information, where required;
- the technical and organisational measures applicable to the transfer; and
- any other information required by the applicable transfer mechanism.
The Merchant may be required to confirm or supplement its account information before the relevant transfer terms can be activated.
Relevant transfer terms may be accepted electronically where legally permissible.
Status of This DPA
This DPA is a standard component of the Coinsnap contractual framework.
It is incorporated into the Coinsnap Terms of Service and is intended to provide a scalable data processing framework for Coinsnap Merchants without requiring separate individually negotiated data processing agreements.
This DPA applies only where Coinsnap processes Personal Data on behalf of a Merchant.
Where Coinsnap processes Personal Data for its own purposes as an independent Controller, that Processing is governed by the Coinsnap Privacy Policy rather than this DPA.
Acceptance of this DPA does not automatically activate any particular international transfer mechanism.
Where an international transfer requires additional contractual safeguards, those safeguards apply only where required for the relevant Merchant, Processing activity, jurisdictions and respective roles of the parties.
Contact
Questions regarding this DPA or requests for information concerning Processing covered by this DPA may be sent to:
Coinsnap / Onlineshop24 DOO
Ljubimira Ivkovica Suce 75
11453 Sopot (Ducina)
Serbia
Email: support@coinsnap.io