DPA — Swan

Data Processing Agreement — Swan

Between:

Effective Date: [DATE] Product: Drop payment services — Banking-as-a-Service (BaaS)


This DPA supplements the generic DPA template (dpa-template.md) with Swan-specific processing details. All general terms from the template apply unless overridden below.


Appendix 1 — Processing Details

Field Description
Purpose Banking infrastructure for Drop: account management, payment initiation (PISP), account information (AISP), transaction processing, and regulatory reporting via Swan's BaaS platform
Nature Collection, storage, processing, and transmission of financial and identity data for payment services
Duration Duration of BaaS service agreement between Controller and Swan
Data subjects Drop end users (account holders), payment recipients, merchants accepting QR payments
Data types Full name, IBAN/account number, bank name, transaction data (amount, currency, timestamp, reference), exchange rates, payment status, balance information, payment initiation requests, beneficiary details for remittance
Special categories None

Appendix 2 — Security Measures (Swan)

  1. Encryption: TLS 1.3 in transit; AES-256 at rest; HSM for cryptographic key management
  2. Access Control: RBAC with MFA, segregation of duties, principle of least privilege
  3. Data Residency: EU data centers (France) — all data processed within EEA
  4. Logging: Complete audit trail for all financial transactions and API access
  5. Data Retention: Transaction data retained per Controller instructions (aligned with bokfoeringsloven 5-year requirement); account data retained during relationship + regulatory period
  6. Incident Response: 24/7 security operations, breach notification within 24 hours
  7. Certifications: PCI DSS Level 1, licensed by ACPR (French banking regulator), PSD2 compliant
  8. Financial Regulations: Compliant with PSD2, EMD2, and applicable French/EU banking regulations

Additional Swan-Specific Terms

Regulatory Compliance

Payment Data

Data Subject Rights

Business Continuity


Signatures

Data Controller — ALAI Holding AS

Name: ___________________________ Title: ___________________________ Date: ___________________________

Data Processor — Swan SAS

Name: ___________________________ Title: ___________________________ Date: ___________________________


Revision #7
Created 2026-02-18 08:44:38 UTC by John
Updated 2026-05-25 07:24:25 UTC by John