πŸ’½GDPR compliance

A brief summary of measures taken at Hyperswitch to ensure GDPR compliance

In this section you will learn about our initiatives to prioritise and improve the security and privacy of Customer Data and Personally Identifiable Information (PII).

The General Data Protection Regulation (GDPR) lays out the definition of Data Controller, Data Processor and Data Subject as below:

Hyperswitch plays the role of a β€˜Data Processor’ and takes all the below initiatives to ensure compliance.

Data Protection and Privacy Principles

Security

Hyperswitch is engineered with a meticulous focus on safeguarding sensitive data aligning with PCI standards. The application also employs various strategies that encompasses various stage, which includes

  • Encryption of Data at rest and Data in Transit

  • Masking of PII information at source

  • Minimizing PII data exposure across the application

  • Secure software development practices

  • SOC Type I and Type II certification

Read more about Data security at Hyperswitch.

Data Retention and Deletion

In the spirit of Data Minimisation principle, we capture data retention and deletion requirements with all our merchants in our DPAs and Master Service Agreement to avoid processing data longer than required. We regularly audit our processes to ensure that the data retention requirements are met.

We support the right to erasure through a permanent deletion of personal data upon request. The Deletion API is published and accessible for all merchants to permanently delete Customer PII Data.

Data Protection Team

Juspay Technologies Private Limited (doing business as Hyperswitch) has a Privacy and Data Protection team and a designated Data Protection Officer to look after Data Protection, Privacy and Compliance Obligations

Data Protection Agreement

Hyperswitch Master Services Agreement includes a Data Protection Agreement which clearly articulates our privacy commitment to merchants. We have evolved these terms and specifically updated these terms to reflect the GDPR from the perspective of payment processing, and, to facilitate merchants’ compliance assessment and GDPR readiness when using Hyperswitch.

Standards and Certifications

We hold ourselves to the highest standards of data security and reliability. We believe in protecting sensitive information and ensuring the utmost trust in our services by our merchants. To achieve that goal we undergo regular audits to address any gaps and strengthen our security and privacy posture.

Use of Sub processors

Below is the list of sub-processors we use at Hyperswitch, as well as the purpose of their use.

Other use cases such as Data Infrastructure, Monitoring Systems are solved by using a self-deployed version of popular open source technologies - Clickhouse, Grafana and Sentry. This provides more control and reduces the need for sharing data and the data being shared across more sub-processors.

Last updated