← Resource centre

POLICIES

Data processing arrangements

Set out the responsibilities for payment-related personal data before production use.

Policy version · 21 September 2026. Read together with the service terms and your applicable written agreement.
01

Data and purpose

Gateway records can include payer numbers and names, amounts, transaction identifiers, receiving account details, receipt text, device information and integration references. Use these records to receive, match, reconcile and investigate payments. Avoid sending personal details that are unnecessary for that purpose.

02

Roles and instructions

The merchant and deployment operator must establish their legal roles and lawful basis for processing in each relevant jurisdiction. A signed data-processing agreement should describe instructions, access, retention, security responsibilities and assistance with data-subject requests. This overview is not an executed DPA.

03

Hosting and international access

Confirm the hosting location, operator access and any onward service providers before onboarding. Cross-border transfer requirements vary by country. No blanket claim of compliance across Africa, data residency or regulator approval is made by this page.

04

Requests and incidents

Route requests through contact@ispbillingpay.com with enough non-sensitive information to identify the account. Identity and authority need verification before disclosure or deletion. Incident notification deadlines and assistance obligations must be defined by applicable law and the agreement.

KEEP EXPLORING

Your next connection starts here.