Purpose
This Data Processing Policy describes how Padi processes personal data on behalf of its users and customers. It outlines our responsibilities regarding data collection, storage, security, access, retention, and deletion.
Effective Date: January 1, 2026
This Data Processing Policy explains how Padi processes, protects, stores, and manages personal information while providing its products and services.
This Data Processing Policy describes how Padi processes personal data on behalf of its users and customers. It outlines our responsibilities regarding data collection, storage, security, access, retention, and deletion.
This Policy applies to all personal data processed through Padi's websites, applications, services, and supporting systems. It applies to customers, authorised users, administrators, and individuals whose data may be processed through the platform.
Where customers upload or manage personal data using the Services, the customer acts as the Data Controller and Padi acts as the Data Processor. Padi processes personal data solely in accordance with documented customer instructions and applicable laws.
Depending on how the Services are used, Padi may process account information, contact information, business records, financial records, transaction information, communication records, system logs, and other information submitted through the platform.
Padi processes personal data only where a valid legal basis exists, including contractual necessity, legitimate interests, legal obligations, user consent, or other lawful grounds recognised under applicable data protection laws.
Padi implements administrative, technical, and organisational safeguards designed to protect personal data against accidental loss, destruction, unauthorised disclosure, alteration, or access. Security measures are reviewed and updated periodically.
Access to personal data is restricted to authorised personnel who require such access to perform their responsibilities. Access permissions are regularly reviewed and monitored.
Padi may engage carefully selected subprocessors to support the provision of Services, including hosting providers, infrastructure providers, communication providers, analytics providers, and payment processors. All subprocessors are required to maintain appropriate safeguards.
Where personal data is transferred across jurisdictions, Padi implements appropriate safeguards to ensure such transfers comply with applicable data protection laws and maintain adequate protection of personal information.
Personal data is retained only for as long as necessary to provide the Services, fulfil contractual obligations, comply with legal requirements, resolve disputes, and enforce agreements.
Upon account closure or customer request, personal data may be deleted in accordance with applicable retention requirements. Certain information may be retained where required by law or necessary for legitimate business purposes.
Padi supports customers in responding to requests relating to access, correction, deletion, restriction, portability, and other rights available under applicable privacy and data protection laws.
Padi maintains procedures for detecting, investigating, responding to, and mitigating security incidents. Where required by law, affected parties may be notified of qualifying incidents.
Padi periodically reviews its internal processes, technical safeguards, and operational controls to ensure continued compliance with applicable legal, contractual, and security requirements.
This Policy may be updated periodically to reflect operational, legal, regulatory, or technological developments. Updates will be published on this page together with the revised effective date.
Questions regarding this Data Processing Policy may be directed to [email protected].