Personal Data Protection and Cyber Security Terms and Conditions

  • By continuing to browse and use Paymob Service, or where any contractual relationship exists between the Parties, You (“You”) agree to comply with and be bound by these Terms and Conditions (“Terms and Conditions”). The Terms and Conditions are hereby incorporated into and form an integral part of the Agreement between Paymob (“Paymob”) and You in the event of any contractual relationship.

  • This Terms and condition apply to all Paymob Group entities and comply with data protection standards, GDPR and applicable Personal Data Protection Laws (PDPL).

  • You and Paymob are referred to individually as “Party” and collectively as “Parties”.

  • Article 1: Definitions and Interpretation:

  • CSP: means “Cloud Service Provider.”

    Cyber Incident Report: means report which includes full details of the security breach or attack, detailing its impact, response, and recommendations.

    Cybersecurity: means the technical and organizational measures implemented by Paymob to ensure confidentiality, integrity, and lawful processing of Data in compliance with applicable data protection and cybersecurity laws.

    Exit Strategy: means a predefined plan ensuring the orderly termination of services, including data retrieval, seamless transfer, secure data deletion, and hardware return) if applicable.

    General Data Protection Regulation (“GDPR”): means to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, which governs the protection of natural persons with regard to the processing of personal data and the free movement of such data.

    Hardware Security Module (HSM): means physical device that securely manages, processes, and stores cryptographic keys to protect sensitive data and transactions.

    “Merchant” means any individual or entity registered with Paymob to use its services. (Hereinafter referred to as the “You”)

    PCI DSS: means Payment Card Industry Data Security Standard, which provides the baseline for what constitutes cardholder data and sensitive authentication data. This standard is created and managed by the PCI Security Standards Council.

    Paymob System: means the Paymob infrastructure technology that provides Paymob Services to its clients and enables it to provide comprehensive solutions within the Territory, facilitating seamless digital transactions and improving access to financial services for its clients in the Territory.

    Paymob Application and/or Paymob App: means the proprietary software system, including its mobile application, web portal, and integrated modules, developed, owned, and operated exclusively by Paymob. The Paymob Application constitutes the sole technical interface utilized by Merchants and Users to access, initiate, and execute actions, including but not limited to transaction processing, reconciliation, reporting, and related services for Paymob Services.

    Personal Data: any data which relates to a natural person if that person can, whether directly or indirectly in conjunction with any other data, be identified from it and includes sensitive personal data.

    Personal Data Protection Law (PDPL): means all applicable laws and regulations relating to the processing of personal data issued within the Territory. These laws and regulations may be amended from time to time by authenticated authorities.

    “Regulated Financial Partners” means banks, payment processors, or other licensed entities engaged in completing transactions.

    Paymob Service: means service pursuant to the Agreement as otherwise agreed with Paymob.

    “User” means any person accessing or interacting with the App or website, whether as a merchant, partner, or customer (Hereinafter referred to as the “You”)

  • Article 2: Term

  • These Terms and Conditions should remain in effect for the duration of the Agreement or the use of Paymob Service. The provisions herein should continue to be binding upon the Parties even after the expiration or termination of the Agreement or cessation of the use of Paymob Services, with respect to any data exchanged during the term of this Agreement, its Appendices, or in connection with the use of Paymob Service.

  • Article 3: Termination of Agreement and Service

  • The Parties agreed that the Paymob should have the right to terminate the Agreement or any of its appendices or the provision of the Paymob Service in the event that You breach any of the provisions of these Terms and Conditions., without prejudice to the Paymob has the right to seek compensation from You for all losses incurred.

  • Article 4: Personal Data Protection

  • 1. The Parties acknowledge that their access to any Personal Data of the other Party, or data that has been transferred, processed, or disclosed, as part of their performance of obligations under the Agreement or any of these Terms and conditions, is strictly conditional upon their full compliance with the data protection provisions set forth herein.

    2. In addition to Personal Data, the Parties acknowledge that they should have access to Personal Data related to the other Party and/or its third parties. The Parties agree to process this Personal Data in accordance with applicable PDPL and in these Terms and Conditions.

    3. The Parties undertake to comply with their obligations under the PDPL and acknowledge that they possess all necessary licenses to protect the data and fulfill the obligations referred to in these Terms and Conditions.

    4. The Parties undertake to maintain an accurate record of data processing activities in accordance with the applicable GDPR and PDPL, regardless of the size or nature of the processing operations.

    5. The Parties should share their internal policies for Personal Data with the other party via email to facilitate mutual understanding and compliance.

    6. The Parties undertake to implement clear procedures to mitigate risks, use and develop technologies to protect Personal Data in accordance with the applicable laws and internal policies shared by the Parties via email in accordance with Article 5.

    7. The Parties should store the information and data in accordance with the applicable PDPL and the internal policies of each party.

    8. The Parties should implement and maintain appropriate technical and organizational measures to store all Personal Data.

    9. The Parties undertake to proactively address all issues, make necessary improvements, and demonstrate compliance with the GDPR and PDPL without any obligation on the non-breaching Party in any way in accordance with the applicable PDPL and the internal policies of Paymob.

    10. The Parties undertake to implement any governmental binding decision in accordance with the Territory’s applicable laws and regulations.

    11. The Parties undertake to take all necessary organizational, administrative, and technical measures to ensure the protection of Personal Data from any leakage during all stages of processing, including Personal Data during the transfer process.

    12. In the event of any losses and/or damages and/or liabilities and/or costs and/or expenses, whether direct or indirect, including reasonable legal costs arising from or related to (a) a breach by either Party of its obligations under these Terms and Conditions., or (b) any act or omission by either Party leading to a violation of applicable data protection laws, including but not limited to the applicable Personal Data Protection Law and its amendments, the Party causing such violation should defend and indemnify the non-breaching Party for all resulting consequences without prejudice to any other rights of the non-breaching Party.

    13. In the event you commit a security breach, fraud, or misuse of the electronic platform provided by Paymob to perform the Services under these Terms and Conditions., You should immediately notify Paymob via email at support@paymob.com.

    14. You acknowledge and agree that it should be solely responsible for all legal obligations and financial burdens resulting from any security or fraudulent incident, including internal fraud by Your employees.

  • Article 5: Cyber Security

  • 1. You should comply with cybersecurity standards by establishing and maintaining effective security controls for any environment, system, or device used to access the Paymob platforms and systems or to store or process confidential information or any data or information related to these Terms and Conditions.

    2. You should implement strict controls to ensure that only authorized people can access Paymob Systems or the information and data, and restrict access to authorized people only, who are bound by the same cybersecurity standards set forth in these Terms and conditions under a legally binding document.

    3. You should ensure confidentiality, integrity, and availability of information and data through encryption and regular backups in accordance with the applicable laws and internal policies of Paymob shared via email in accordance with Clause (4.5)

    4. You should develop and maintain an incident response plan to address, respond to, and/or mitigate cybersecurity incidents immediately.

    5. You should follow the below listed plan in case of any incident:

    a. Informing Phase: You should inform Paymob immediately, not later than 6 hours on a 24/7 basis, when a cybersecurity incident has occurred and been identified, and be in direct communication with Paymob.

    b. Reporting Phase: You should submit an Initial Cyber Incident Report. While incidents categorized as ‘Major’ risk are to be reported to Paymob within 12 hours from the time of occurrence, those categorized as ‘Medium’ and ‘Low’ risks are to be reported to Paymob within 24 hours and 48 hours respectively. The initial report should include the data of the final report and resolution of the incident and return to normal process.

    c. Incident Situation Report: You should submit the Incident Situation Report if there are new updates on the earlier reporting until the final resolution of the incident/issue.

    d. Incident Closure Report: You should submit the Incident Closure Report after resuming normal operations.

    6. Paymob has the right to terminate the Agreement immediately in the event of any cyber incident, and You should be liable for any penalty from any regulatory body, while Paymob retains the right for damage compensation.

    7. You should train and educate all its employees and/or affiliates who have access to data or information on cybersecurity risks and how to predict and address them. You should be responsible for all actions of its affiliates and the resulting consequences in this regard.

    8. You should operate and implement periodic password update controls for authorized people to access the data and information, as well as use and update antivirus software for all devices connected to the same network through which data and information can be accessed.

    9. Upon expiration or termination of the Agreement, You should: (a) promptly return all Paymob data and information; (b) securely delete all copies thereof; and (c) cooperate fully with a final security audit by Paymob to verify compliance with data deletion requirements.

    10. You should continuously monitor information systems to detect and respond to cybersecurity threats, establish a mechanism for reporting any cybersecurity incidents, and ensure that Paymob and the authorities are promptly notified of any discovered cybersecurity event.

    11. In the event You fail to mitigate a security vulnerability, You should immediately notify Paymob and disclose all potential security vulnerabilities that may facilitate the exchange of information and data. Failure to comply with this notification requirement should result in liability for any resulting damage.

    12. You acknowledge and agree that Paymob and the Central Bank in the Territory or its deputed representatives should have the right to conduct security audits, compliance inspections, and forensic investigations at any time during the term of the Agreement.

    13. You should ensure that its systems comply with current PCI Data Security standards and any amendments thereto from time to time.

    14. You should indemnify Paymob in the event of any incident or losses and/or damages and/or liabilities and/or costs and/or expenses, whether direct or indirect, including reasonable legal costs arising from or related to (a) a breach of its obligations under this clause, or (b) any act or omission leading to a violation of Paymob cybersecurity, or (c) breach of its obligations under these Terms and Conditions.

    15. You acknowledge that You agreed and reviewed on Paymob Cybersecurity policy, and general and private obligations for cybersecurity before using or accessing Paymob platform or resources.

    16. You should comply with all applicable laws and regulations, Paymob Cybersecurity policy, security requirements, including Data Protection, access control, and incident reporting. In the case of default by You, Paymob has the right to terminate the Agreement immediately, and You should be liable for any penalty applied by the governmental and/or regulatory authorities and/or banks while Paymob retains the right to compensate for damages.

    17. You acknowledge and ensure secure hardware and software installation, maintenance, and timely updates to prevent vulnerabilities.

    18. You should maintain an updated list of authorized users with defined access privileges to Paymob System.

    19. You should remove access rights for the users immediately upon the termination of the Agreement or after notice from Paymob to remove the access of a user.

    20. You should align with Paymob and follow the agreed process of Change Management Process or system modification, including security risk assessments, without any effect on the stability of the Service.

    21. You should follow the escalation process for resolving cybersecurity incident and compliance issues as per the matrix mentioned in these Terms and Conditions. In the case of default, Paymob has the right to terminate the Agreement, and You should be liable for any penalty from the regulatory bodies while Paymob retains the right for damage compensation.

    22. You acknowledge that all sensitive data should be end-to-end encrypted, while double encryption may be considered based on the risk assessment.

    23. You should establish encryption processes, a robust cryptographic key management policy, standards, and procedures covering key generation, distribution, installation, renewal, revocation, recovery, and expiry.

    24. You acknowledge that the encryption keys and other forms of authentication should be kept under the control of Paymob and should be stored in an appropriate Hardware Security Module (HSM) where technically feasible. In case the encryption keys are kept with You, in exceptional circumstances, it should be subject to appropriate risk management and controls to protect data confidentiality, data integrity, and authenticity.

    25. Upon termination or expiration of these Terms and Conditions., You should follow and execute an Exit Strategy to ensure: (a) complete data retrieval and transfer to Paymob in a Paymob-specified format; (b) irreversible deletion of all Paymob data and provision of verifiable proof; (c) smooth transfer of all activities and processes; and (d) return of any dedicated Paymob hardware. You agree that Paymob should have the right to conduct audits, examinations, and reviews of You’s systems, including cybersecurity and forensic audits, and to access third-party audit reports and Vulnerability Assessment and Penetration Testing (VA&PT) results.

    26. You should implement a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) and must notify Paymob of any service disruptions.

  • Article 6: Notice

  • Notices under these Terms and Conditions. Will be valid and have legal effect if sent by email, certified mail with return receipt, or international courier, to the respective addresses shown above or such other address as either party should designate. Notice should be deemed given when received.

    In the case of Paymob:

    Official notices: legal@paymob.com

    Official Email for Cyber Security and Personal Data: security@paymob.com

    Support: support@paymob.com

    In the case of Your Email address registered or specified in the Agreement or recorded through registration at Paymob App or official website.

  • Article 7: Severability

  • Unless otherwise stated in these Terms and Conditions, all of the terms, provisions, requirements, and specifications contained in the Agreement remain in full force and effect. In the event of any conflict or inconsistency between the provisions of the Agreement and these Terms and Conditions, the provisions of the latter should prevail.

  • Article 8: Governing Law

  • 1. The governing law of these Terms and Conditions should be the substantive law of the nation where the Service is provided. Any dispute arising out of or in connection with these Terms and Conditions should be referred to and finally resolved by the competent courts of such a nation.

    2. You hereby acknowledge that you have read, understood, and expressly agreed to be bound by the above-mentioned Terms and Conditions.

Return to home image image