Aida Merchant Services · Legal

Data Protection & Processing Terms

1. Roles and scope

The merchant (the customer) is the controller and Aida is the processor for personal data placed in its merchant account or workspace. Processing lasts for the customer’s use of the service and any limited deletion or backup period. Its purpose is to record sales, payments, refunds and payouts; keep customer, loyalty, offer and invoice records; send receipts and invoices; produce reports and exports; and provide customer-requested integrations.

2. Data and people covered

Data may include the names and contact details of the merchant’s customers, purchase and transaction history, loyalty balances and reward activity, offer redemptions, business-customer company and billing details (such as CVR or VAT number, EAN number and billing address), invoices and B2B orders, receipts, staff names, roles and shift records, notes, uploaded files and technical identifiers. Data subjects may include the merchant’s customers (consumers and business contacts), staff and users, suppliers and other business contacts. Customers must avoid uploading special-category or highly sensitive personal data unless Aida has agreed in writing that the service is suitable for it.

3. Customer instructions

Aida processes customer personal data only on documented instructions expressed through the service, these terms, support requests and connected integrations, unless EU or Danish law requires otherwise. Aida will inform the customer if an instruction appears to violate data-protection law, unless prohibited by law.

4. Confidentiality and security

People authorized to process customer data are bound by confidentiality. Safeguards include authenticated account access, workspace and role checks, encrypted transport, encrypted saved integration credentials, server-side secret handling, input limits and validation, tenant separation, controlled imports, audit-style activity records, backups or recovery mechanisms where available, and monitoring of operational errors. Security is reviewed in light of the risk, available technology and the nature of this early-access service.

5. Subprocessors

The customer gives general authorization for subprocessors needed to run the service. Current categories and providers are: hosting, storage and inbound email routing through Cloudflare; sign-in through Supabase; payments through Stripe; AI processing through OpenAI; outgoing email through Resend; and company mailboxes through Google Workspace. Aida remains responsible for its processor obligations and will require appropriate data-protection commitments. The current provider list is published on the Subprocessors page. Aida will give at least 30 days’ notice of a material addition where reasonably possible. A customer may object on reasonable data-protection grounds by contacting Aida.

6. International transfers

Where customer personal data is transferred outside the EEA, Aida will use a valid transfer mechanism required by applicable law, such as an adequacy decision or Standard Contractual Clauses, and apply supplementary safeguards where appropriate.

7. Assistance

Taking account of the nature of processing, Aida will reasonably assist the customer with data-subject requests, security obligations, breach assessment, data-protection impact assessments and regulator consultations. The customer remains responsible for its notices, legal basis, data accuracy, retention rules and responses as controller.

8. Incidents

Aida will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and will provide available information needed for the customer’s assessment and notifications. Customers should report suspected incidents immediately using the contact details below.

9. Return and deletion

On termination or written request, Aida will delete or return customer personal data, at the customer’s choice where technically available, unless applicable law requires retention. Deletion may take additional time to propagate through protected backups. Customers should export needed records before closing an account.

10. Information and audits

Aida will make information reasonably necessary to demonstrate compliance with processor obligations available to the customer. Audits must protect other customers, confidential information and system security; documentary review or independent reports should be used first, with any further inspection coordinated in advance and limited to what is legally necessary.

11. Order of terms

If these Data Protection terms conflict with the Terms of Service on processing customer personal data, these Data Protection terms control. Any mandatory requirements of applicable data-protection law continue to apply.

Contact

Aida Merchant Services, operated by Gabriel Gerrits, Odense, Denmark.

Questions or requests can be sent through our Contact page or by phone on +45 25 56 07 08.