LEGAL / DATA PROCESSING

Data Processing Terms

When your customers' information flows through Paradox, you are the controller of that data and Paradox is your processor. This page describes that relationship in plain language.

Last updated August 8, 2026

1. Roles

For your customers' personal data — names, emails, phone numbers, billing addresses, payment history — you decide what is collected and why (the "controller"). Paradox processes that data only to provide the service, on your instructions, and never for our own purposes (the "processor"). For your own account data, Paradox is the controller as described in the Privacy Policy.

2. What processing happens

  • /Storing customer contact details and payment metadata you enter or import.
  • /Charging stored payment profiles at your gateway on the schedules you configure.
  • /Sending invoices, receipts, reminders and card-update emails from your business identity.
  • /Reconciling your transactions against your processor's settlement reports.

3. Subprocessors

Paradox uses a deliberately short list of subprocessors:

  • /Fiserv / CardConnect — payment processing and card tokenization (under your own merchant agreement).
  • /Twilio SendGrid — transactional email delivery.
  • /Twilio — text-message delivery, only for customers who opted in.
  • /Infrastructure hosting — the servers and managed database the service runs on.

We'll update this page before adding a new subprocessor that touches customer personal data.

4. Security measures

  • /TLS encryption for all data in transit.
  • /AES-256 encryption at rest for gateway credentials; write-only API passwords that are never displayed back.
  • /Card numbers architecturally excluded — card entry happens in Fiserv's hosted frame and only tokens reach Paradox.
  • /Role-based access within your workspace and an audit trail of significant actions.

5. Deletion, export and breach notice

You can export transaction data any time from the app. On account closure we delete customer personal data on request within 30 days, except records retained under financial-record laws. If a personal data breach affects your customers' data, we will notify you without undue delay so you can meet your own obligations.