Data processing addendum
How Payinference processes the limited data you send it when it acts as your processor.
Last updated July 19, 2026
Roles
For the payment context your systems send to the Decision API, you are the controller and Payinference is the processor. Payinference processes that data only to provide the service described in the terms.
Data in scope
Processing covers the schema limited payment context, the decisions computed from it, the outcomes you report and operational telemetry built from bucketed amounts and hashed merchant identifiers. Cardholder data is out of scope by design. The API schemas reject card numbers, CVV codes and cardholder identity at the boundary.
Processing purposes
Data is processed to compute decision instructions, maintain provider health and pricing signals, and present your workspace its own analytics and audit history. Payinference does not use your data for its own marketing.
Security measures
The strongest measures are architectural and are described on the security page. Strict schemas keep sensitive payment data out of the system entirely, dashboard access is role based, provider secrets are write only once set, and administrative actions are recorded in audit logs.
Subprocessors
This draft does not list subprocessors. The executed agreement will name the current infrastructure providers and the mechanism for notifying you of changes.
Deletion and return
When the agreement ends, workspace data is deleted on your request, subject to records we must keep by law.
Audit support
Every decision is stored with its inputs, matched policy rules, reason codes and reported outcome, so the processing that matters most to you is inspectable from your own dashboard.
