Data processing addendum
The processor terms that apply when the platform handles personal data on a customer's instruction.
The WinkPG platform default. An operator may replace it with their own text. Last reviewed 20 September 2026.
Roles
The customer is the controller of the personal data they submit. WinkPG is the processor of that data and processes it only on the customer's documented instruction, which includes the instruction implied by using the service as it is documented.
Where the platform processes data about its own users for its own purposes, it acts as a controller, and the privacy policy covers that role.
Subject matter and duration
The subject matter is the processing needed to provide payment gateway services. The duration is the term of the agreement, plus the retention periods the retention schedule states for records that must outlive it.
Categories of data and data subjects
Data subjects: the customer's own staff with platform accounts, and the payers whose transactions the customer submits.
Categories: identification and contact data, payment instrument data, transaction and billing data, and the technical and usage data a request generates. No special category data is required by the service, and the customer is asked not to submit any.
Security measures
Cardholder data is encrypted at the field level with AES-256-GCM under keys held in a managed key vault. Card verification values, PINs and full magnetic stripe or chip data are never stored.
Traffic is protected in transit with TLS 1.2 as a minimum on every public domain, host and data store.
Access is granted on a least privilege basis through a role model with per operation checks and a default of deny. Administrative actions are recorded in an audit log with the values before and after the change.
The security and compliance overview describes the wider control set, and the evidence behind each control is available through the trust document library.
Subprocessors
The platform engages the subprocessors listed on the subprocessor page, each under a written contract imposing data protection obligations no weaker than these.
A customer is notified of an intended addition or replacement with enough notice to object. The subprocessor page is the authoritative list and carries its own review date.
Assistance to the controller
The platform assists the customer in answering a data subject request, in carrying out a data protection impact assessment, and in consulting a supervisory authority, to the extent the customer cannot do so through the application itself. Export and erasure are available in the application.
The platform notifies the customer without undue delay after becoming aware of a personal data breach affecting the customer's data, with the detail the customer needs to meet their own notification duty.
Audits
The platform makes available the information needed to demonstrate compliance with these terms, through the compliance materials in the trust document library and, where the agreement provides for it, through an audit conducted on the terms it sets.
International transfers
Where personal data is transferred out of the jurisdiction it was collected in, the transfer relies on an adequacy decision, on standard contractual clauses, or on another lawful transfer mechanism named in the signed agreement.
Return and deletion
At the end of the agreement the platform deletes the customer's personal data or returns it, at the customer's choice, except where a record must be retained to meet a legal obligation. The retention schedule names those records.
Evidence and compliance materials
This surface states posture and publishes no evidence. The attestations, reports and control matrices behind these statements are in the trust documents catalogue, where a signed-in developer account can retrieve them and every retrieval is recorded.