Legal

Data Processing Policy

Effective Date: January 1, 2026

This Data Processing Policy explains how Padi processes, protects, stores, and manages personal information while providing its products and services.

01

Purpose

This Data Processing Policy describes how Padi processes personal data on behalf of its users and customers. It outlines our responsibilities regarding data collection, storage, security, access, retention, and deletion.

02

Scope

This Policy applies to all personal data processed through Padi's websites, applications, services, and supporting systems. It applies to customers, authorised users, administrators, and individuals whose data may be processed through the platform.

03

Roles and Responsibilities

Where customers upload or manage personal data using the Services, the customer acts as the Data Controller and Padi acts as the Data Processor. Padi processes personal data solely in accordance with documented customer instructions and applicable laws.

04

Categories of Data Processed

Depending on how the Services are used, Padi may process account information, contact information, business records, financial records, transaction information, communication records, system logs, and other information submitted through the platform.

05

Lawful Processing

Padi processes personal data only where a valid legal basis exists, including contractual necessity, legitimate interests, legal obligations, user consent, or other lawful grounds recognised under applicable data protection laws.

06

Data Security

Padi implements administrative, technical, and organisational safeguards designed to protect personal data against accidental loss, destruction, unauthorised disclosure, alteration, or access. Security measures are reviewed and updated periodically.

07

Access Controls

Access to personal data is restricted to authorised personnel who require such access to perform their responsibilities. Access permissions are regularly reviewed and monitored.

08

Subprocessors

Padi may engage carefully selected subprocessors to support the provision of Services, including hosting providers, infrastructure providers, communication providers, analytics providers, and payment processors. All subprocessors are required to maintain appropriate safeguards.

09

International Transfers

Where personal data is transferred across jurisdictions, Padi implements appropriate safeguards to ensure such transfers comply with applicable data protection laws and maintain adequate protection of personal information.

10

Data Retention

Personal data is retained only for as long as necessary to provide the Services, fulfil contractual obligations, comply with legal requirements, resolve disputes, and enforce agreements.

11

Data Deletion

Upon account closure or customer request, personal data may be deleted in accordance with applicable retention requirements. Certain information may be retained where required by law or necessary for legitimate business purposes.

12

Data Subject Rights

Padi supports customers in responding to requests relating to access, correction, deletion, restriction, portability, and other rights available under applicable privacy and data protection laws.

13

Security Incidents

Padi maintains procedures for detecting, investigating, responding to, and mitigating security incidents. Where required by law, affected parties may be notified of qualifying incidents.

14

Audits and Compliance

Padi periodically reviews its internal processes, technical safeguards, and operational controls to ensure continued compliance with applicable legal, contractual, and security requirements.

15

Changes to this Policy

This Policy may be updated periodically to reflect operational, legal, regulatory, or technological developments. Updates will be published on this page together with the revised effective date.

16

Contact Information

Questions regarding this Data Processing Policy may be directed to [email protected].