NAYAX DATA PROTECTION ADDENDUM

This Data Protection Addendum (“DPA”), as well as the provisions of the agreement between Nayax and Customer (“Agreement”), govern the transfer and Processing of Personal Data between NAYAX and the Customer within the scope of the SYTE Service. Any capitalized terms that are used herein and not defined herein shall have the meaning ascribed to such terms in the Agreement.

  1. DEFINITIONS
    1. The terms “Personal Data,” “Processor,” “Controller,” and “Processing,” “Special Categories of Personal Data,” shall have the meaning ascribed to such terms in the GDPR and the UK GDPR. The terms “Business,” “Business Purpose,” “Consumer,” “California Consumer,” “Service Provider” and “Sell” or “Sale” shall have the meaning ascribed to them in the CPRA. The term “Personal Data” as used herein shall also mean and refer to “Personal Information” as such term is defined in the CPRA.
    2. Authorized User” means an individual who is authorized by Customer to use the Services, to whom Customer has provided a sub-account, and/or to whom Customer has provided user credentials – identification and password enabling access to the Customer Account. Authorized Users may include, for example, employees, consultants, contractors and agents of Customer.  
    3.  “CPRA” means the California Privacy Rights Act of 2020, Cal. Civ. Code §§ 1798.100 et. Seq. and the regulations at 11 C.C.R. §§7000 et seq.
    4.  “Customer Account” shall have the meaning ascribed to such term in Section 3.
    5. Customer’s End-Users” means Customer’s end-users and consumers. 
    6. Data Protection Law” means any and all applicable privacy and data protection laws and regulations (including, where applicable, the EU GDPR, UK GDPR (namely, the UK Data Protection Act 2018 and the European Union (Withdrawal) Act 2018 as amended by Schedule 1 to the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419)), and the CPRA and the Israeli Protection of Privacy Law, 5741-1981 and the regulations enacted thereunder) as may be amended or superseded from time to time. 
    7. Data Subject” means a natural person regarding whom Personal Data or Personal Information is Processed and shall also mean and refer to a “Consumer” under the CPRA.
    8. End-User Data” means any and all Personal Data relating to the End-Users which is processed within the scope of the Services. 
    9.  “GDPR” means EU General Data Protection Regulation (Regulation 2016/679).
    10. Syte Services” means the provision of the Platform. 
    11. Platform” means the NAYAX visual search platform that integrates into e-commerce websites, enabling product discovery through AI-powered image recognition.
    12. UK GDPR” means the Data Protection Act 2018 and the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 and as amended by Schedule 1 to the Data Protection, Pr
  2. DATA PROCESSING
    1. The parties acknowledge that in relation to all End-User Data, Customer shall be regarded as the Controller of End-User Data, and NAYAX shall be regarded and is acting as a Processor of the End-User Data on behalf of the Customer. For the purposes of the CPRA (and to the extent applicable), Customer is the Business and Nayax is the Service Provider. Without derogating from the above, it is hereby clarified that in addition to Nayax’s capacity as a Processor of the End-User Data, Nayax is also a Controller of certain Personal Data related to the Customer, such as (without limitation) Personal Data related to Customer’s Authorized Users or other employees and personnel of the Customer, to the extent provided. Any Personal Data Processed by Nayax as a Controller shall be used and processed in accordance with Nayax’s Privacy Policy referenced below and is not governed by this DPA which governs solely the Processing of Personal Data by Nayax as a Processor on behalf of Customer.
    2. NAYAX will Process Personal Data on behalf of Customer as specified in ANNEX I attached hereto.
    3. NAYAX will Process Personal Data other than on behalf of Customer, for the purpose of providing its services under the Agreement, as further described in NAYAX’s Privacy Policy.
  3. CUSTOMER ACCOUNT MANAGEMENT
    1. In order to use the Platform a designated Customer account will be created by Nayax for the use of the Customer and its Authorized Users (“Customer Account” or “User Account“). Customer will be required to select a username and password and if needed, use a 2 factor authentication application in order to use the Platform. Customer may create sub-accounts and grant access authorizations to the Customer Account solely to its Authorized Users. Each of the Authorized Users will be required to select a username and password in order to access and use their sub-account in the Customer Account. Customer is solely responsible for setting-up applicable permissions and sub-accounts on the Platform for each of its Authorized Users. 
    2. Customer acknowledges that under applicable laws access authorizations to systems containing Personal Data, including the Platform, should only be granted on a need-to-know basis, may require ongoing monitoring of access authorizations and should be used by Authorized Users only. Customer may need to remove Authorized Users who no longer have a “need to know” with respect to the Platform as a part of such monitoring, such as any of Customer’s former employees. Customer hereby undertakes to comply with applicable laws in this context.
    3. In order to create and use the User Account, Customer and any Authorized Users on its behalf, must be at least 18 years old, and will be required to provide certain Personal Data, such as their name and contact information. All such information provided must be truthful, and accurate and up-to-date. Customer undertakes that it and its Authorized Users will not, and will not enable others, to use any access authorizations in deviation of the specific authorization granted or by anyone who is not the Authorized User, and not to share their authorizations with any other person or third party. If Customer’s or its Authorized Users’ information provided during the Platform registration process changes at any time, Customer undertakes to update such information on the Customer Account or as otherwise instructed to do so by NAYAX.
    4. Customer hereby represents and warrants that it: (i) is solely responsible for Authorized Users’ compliance with this DPA, any applicable agreement with NAYAX, and any applicable laws and regulations; (ii) is solely responsible for the accuracy, quality and legality of any information provided by it or its Authorized Users; (iii) is solely responsible for its use and the Authorized Users’ use of the Services and the Platform; (iv) will use appropriate efforts to prevent and detect unauthorized access to or use of the Services and the Platform and notify Nayax of any such unauthorized access or use immediately upon discovery; and (v) will use the Services and the Platform only in accordance with this DPA, the Terms and Conditions and applicable laws. 
    5. For the avoidance of doubt, Nayax does not and cannot control or monitor the management of the Customer Account and use of the Platform by Customer and its Authorized Users, and Customer is solely and fully responsible for such management and use. 
    6. In the event Customer or its Authorized Users violate any of the terms of this DPA, NAYAX may suspend or terminate the Customer Account or suspend or terminate Customer or its Authorized Users’ access to the Platform.
  4. REPRESENTATIONS AND UNDERTAKINGS OF THE PARTIES
    1. The Parties shall each implement appropriate technical and organizational measures to ensure a level of security appropriate for the risks to Personal Data.
    2. Reserved
    3. NAYAX represents and warrants that NAYAX’s employees, authorized by NAYAX to Process Personal Data on behalf of Customer, are committed to customary confidentiality undertakings and privacy and data protection obligations, or are otherwise under appropriate statutory obligations of confidentiality. 
    4. NAYAX shall only Process Personal Data on behalf of Customer, pursuant to the instructions as set forth herein and in accordance with the Agreement.   
    5. Customer undertakes that Customer shall Process Personal Data only as lawful and compliant with applicable law and that it will comply with applicable Data Protection Law, specifically with regards to the lawful basis principal for Processing Personal Data under the GDPR, UK GDPR and the CPRA (if applicable). 
    6. Customer further represents that Customer has all required authorizations to disclose Personal Data to NAYAX, including, where required, procuring an affirmative act of consent from End-Users in the event Customer is required to do so in accordance with applicable Data Protection Law. Furthermore the Customer shall maintain all necessary notices and uphold any and all privacy requirements under applicable Data Protection Law that it will need in order to Process Personal Data in accordance with the terms of this DPA.
    7. Customer shall not disclose to NAYAX any Data that is considered Special Categories of Personal Data. 
    8. NAYAX will delete or return to the Customer, any of Customer’s Personal Data and the End-User Data that NAYAX Processes on behalf of Customer, after the termination or expiration of the Agreement, unless permitted or required to retain it under applicable law.
  5. INSTRUCTIONS
    1. Customer hereby instructs NAYAX to Process, on behalf of Customer, Personal Data, in connection with the Services to Customer, and as set forth under Article 28(3) of the GDPR and UK GDPR (as applicable) solely for the purposes and in accordance with the terms specified herein and in the Agreement and for the pursuit of a Business Purpose as set forth under the CPRA. Notwithstanding the above, in the event NAYAX is required under applicable laws to Process End-User Data, other than as instructed by the Customer, NAYAX shall make reasonable efforts to inform the Customer of such requirement prior to Processing such End-User Data, unless prohibited under applicable law from doing so. 
    2. Notwithstanding the above, NAYAX will not be obligated to perform any instruction which in NAYAX’s determination, is in violation of applicable law.
  6. AUDITS
    Upon Customer’s reasonable request, and no more than once per calendar year (unless applicable law requires otherwise), NAYAX will provide Customer with relevant documentation or records (which may be redacted to remove confidential commercial information) which will enable it to verify NAYAX’s compliance with its data protection and security obligations under the terms of this DPA. NAYAX shall supply such documentation to Customer within thirty (30) days from its receipt of such request in writing, at Customer’s expense.
  7. DATA SUBJECTS’ RIGHTS AND AUTHORITY REQUESTS
    1. Customer shall have the sole liability to comply with its obligations in connection with the rights and freedoms of Data Subjects pursuant to applicable laws. It is therefore hereby agreed, that in the event NAYAX receives a request from a Data Subject or an applicable authority in respect of the Personal Data Processed by NAYAX on behalf of the Customer, where relevant and unless otherwise required under applicable law, NAYAX will direct the Data Subject or the applicable authority to the Customer in order to enable the Customer to respond directly to the Data Subject’s or the applicable authority’s request, unless otherwise required under applicable laws. 
    2. NAYAX shall make reasonable commercial efforts to assist the Customer, in the fulfilment of the Customer’s obligations to respond to Data Subjects’ request to exercise their rights, to the extent permitted under Data Protection Law.
  8. NO SALE OF PERSONAL DATA
    It is hereby agreed that any sharing of Personal Data between the parties is done solely in order to fulfil a Business Purpose and NAYAX does not receive or process any Personal Data in consideration for the Services. As such, the Processing of such Personal Data shall not be considered a Sale under the CPRA. 
  9. CUSTOMER’S PERSONNEL DATA RIGHTS
    Nayax will Process certain Personal Data regarding Customer’s personnel interacting with Nayax in relation to the Services. Such Processing will be done in accordance with NAYAX’s Privacy Policy and User Rights Policy, undertakes to inform its personnel of such Processing and refer them to the above mentioned policies. 

    Customer’s personnel have certain rights with respect to their Personal Data as further explained in Nayax’s Privacy Policy. Customer undertakes to inform its personnel regarding any Processing activities conducted by Nayax, including referring them to Nayax’s Privacy Policy for further information.
  10. SUBPROCESSING AND TRANSFER OF PERSONAL DATA TO THIRD PARTIES
    1. Customer hereby grants NAYAX express authorization to engage with third party data Processor’s (“Sub-Processors”) for the provision of the Services, as determined by NAYAX in NAYAX’s reasonable determination. A list of NAYAX’s Sub-Processors can be found here, as may be updated from time to time by Nayax (“Authorised Sub-processors”). 
    2.  Customer confirms that Nayax will update the list of Authorised Sub-processors from time to time, will inform the Customer in advance of any updates taking effect. In the event that Customer has an objection to the transfer of its Personal Data to any third party listed in the updated list of Authorised Sub-processors, Customer will provide written notification to Nayax, specifying the relevant third party and the grounds for the objection. Following the receipt of such notification, Nayax may either: (i) replace the relevant third party in relation to sub-processing of Customer’s Personal Data; or, if such replacement is not practical (ii) terminate the Agreement by written notification to Customer.    
    3. Customer acknowledges that certain third parties with which Nayax shares Personal Data in the framework of providing the Customer with the Services, may be considered as a Controller under the GDPR, UK GDPR or under the applicable credit card scheme, or a Business under the CPRA. In relation to such third parties, Customer confirms that they have separate and independent responsibility to Process Personal Data in compliance with applicable Data Protection Laws, and that Nayax will not be liable for such entities’ Processing activities and their compliance with applicable Data Protection Laws. 
    4. NAYAX may also share Personal Data with its affiliated companies in the Nayax group, as reasonably required to conduct its business and provide Customer with the Services. 
  11. NOTIFICATIONS 
    1. NAYAX shall notify Customer in writing in the event that it becomes aware of a data breach that affected Customer’s Personal Data or End-User Data, and/or as otherwise required under applicable law. NAYAX’s notification regarding or response to a data breach shall not be construed as an acknowledgment by NAYAX of any fault or liability with respect to such data breach. NAYAX will take any reasonably necessary steps to contain, remediate and minimize the effects of the data breach and co-operate with the Customer with respect to the handling of such data breach (as applicable and necessary).
    2. NAYAX may disclose Data to law enforcement, regulatory or other government agencies, or third parties, if NAYAX reasonably believes that such disclosure is necessary to comply with a judicial proceeding, court order, or a legal process.
  12. LIABILITY AND INDEMNIFICATION
    Customer will indemnify, and hold harmless NAYAX, and its officers, directors, employees, successors, and agents, from all damages and liabilities (including, without limitation, reasonable attorneys’ fees and legal expenses), resulting from any claim by a third party (including supervisory authorities) that arises out of a violation of the Customer’s representations and/or obligations under this DPA or applicable laws. 
  13. TERM
    The term of this DPA shall continue until the termination or expiration of the engagement between NAYAX and Customer.
  14. GENERAL TERMS.
    1. Some of the above Sections shall be in force only in the event the GDPR, UK GDPR or the CPRA (as applicable) applies to the Processing of Personal Data pursuant to this DPA. 
    2. In the event of inconsistencies between the provisions of this DPA and the Agreement, the provisions of this DPA shall prevail. 
    3. NAYAX may amend this DPA from time to time, and make the amended DPA available to Customer. 
    4. In the event this DPA is translated into a different language other than English and in the event there are any discrepancies between the English version of this Agreement and the translated versions, the English version of this DPA shall prevail.

ANNEX I: DETAILS OF PROCESSING AND TRANSFERRING OF PERSONAL DATA

  1. This ANNEX I includes certain details of the Processing of Personal Data as required by Article 28(3) GDPR or by UK GDPR (as applicable) and the transferring Personal Data. Subject matter and duration of the Processing of Personal Data
    • The subject matter and duration of the Processing of the Personal Data are set out in Section 2 of this DPA.
  2. The nature and purpose of the Processing of Personal Data
    NAYAX will be providing Customer with the Services which involve the processing of Personal Data. The scope of the Services is set out in the Agreement, and the Personal Data will be processed by NAYAX under the instructions of Customer, solely for the purpose of providing the Payment Services to Customer and to comply with the terms of the Agreement and this DPA.   
    • The types of Personal Data to be processed and transferred pseudonymized user ID;
  3. The categories of Data Subjects to whom the Personal Data relates 
    • Customers’ End-Users
  4. Sensitive data processed or transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measure:
    • N/A
  5. The obligations and rights of Customer 
    • The obligations and rights of Customer are set out in the Agreement and this DPA.
  6. The processing operations carried out in relation to the Personal Data 
    • Collection, recording, hosting, organizing, adapting, analyzing, retrieving, sharing with Sub-Processors, structuring, storing, deleting, in each case for the purposes of providing the Services to Customer, the scope of which are set out in the Agreement and this DPA.
  7. The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis).
    • Continuous