Skip to main content
DATA PROCESSING AGREEMENTOrganizations

Data Processing Agreement

Effective Date: August 4, 2026

This Data Processing Agreement (DPA) describes how RunPayway™ Processes Personal Data on behalf of the organizations that use it to establish a requested financial fact about a person they serve.

PeopleStar Enterprises, INC. · Orange County, California, USA

1. Definitions

"Controller" means the entity that determines the purposes and means of Processing Personal Data. For information about a person a request is about, the Controller is the Customer organization.

"Processor" means the entity that Processes Personal Data on behalf of the Controller, which is PeopleStar Enterprises, INC. (RunPayway™).

"Personal Data" means any information relating to an identified or identifiable natural person that the Customer provides through the RunPayway™ service.

"Processing" means any operation performed on Personal Data, including collection, storage, use, evaluation, and deletion.

"Authorized User" means a member of the Customer’s staff to whom the Customer has issued a RunPayway™ account.

"Sub-processor" means any third party engaged by the Processor to Process Personal Data.

2. Scope of Processing

RunPayway™ Processes the following categories of Personal Data: the Customer’s own reference for the person a request is about, any external case or source-system reference the Customer attaches, the financial fact and threshold requested, the figures and evidence status recorded for that request, including, where a governed evaluation is run on figures supplied by staff, the proposed terms, income structure, recurring obligations and financial margin, and the work email address, display name and staff role of each Authorized User.

Processing is performed solely to run the RunPayway™ evaluation for the Customer, to return a completed result or a refusal naming what is unresolved, and to hold the resulting record for the Customer.

RunPayway™ does not collect bank credentials, account numbers, credit reports, credit scores, transaction history, or government identification numbers, and has no connection to any bank, credit bureau, payroll provider, or lender system.

The RunPayway™ evaluation is deterministic and runs under a recorded method version. Personal Data is not used for model training or profiling. The result is information for the Customer and is not a loan approval, a denial, or an automated decision producing legal or similarly significant effects. The Customer makes its own decision through its own process.

RunPayway™ does not require the name of the person a request is about. A Customer may identify that person by case reference alone.

3. Obligations of the Processor

Process Personal Data only on documented instructions from the Controller, unless required by law.

Ensure that persons authorized to Process Personal Data have committed to confidentiality.

Implement the technical and organizational measures described in Section 5 and in the published RunPayway™ Security Practices.

Not engage another Processor without prior notice to the Controller.

Assist the Controller in responding to data subject access, rectification, erasure, and portability requests.

Delete or return Personal Data at the end of the service relationship, at the Controller’s choice.

Make available to the Controller the information reasonably necessary to demonstrate compliance with this agreement.

4. Sub-processors

RunPayway™ uses sub-processors for infrastructure hosting and network delivery. The current list for a Customer’s deployment is provided on request through the contact form or the privacy request form.

No sub-processor is used for payment processing, credit data, or lender integration, because RunPayway™ performs none of those functions.

The Controller is notified of any intended change to sub-processors and may object within 30 days.

Each sub-processor is bound by data protection obligations no less protective than those in this agreement.

5. Data Security

Data in transit is encrypted using HTTPS.

Access to any record requires authentication. Passwords are stored only as salted hashes derived with a slow key-derivation function, and session tokens are stored only as hashes and expire.

Each record is owned by exactly one organization. Every read and write is scoped on the server to the organization of the signed-in user, and the organization is taken from the validated session rather than from any value supplied by the browser.

Staff roles limit what an Authorized User may do. An organization administrator manages users and settings, an assessor creates and updates records, and a read-only reviewer may view but not modify.

Personal Data is not sold, rented, or shared with third parties for marketing purposes.

RunPayway™ has not completed an independent security audit and holds no security certification. This section describes implemented measures and is not a warranty.

6. Data Subject Rights

Data subjects may request access to, rectification of, or deletion of their Personal Data.

These rights include, where applicable under GDPR: access (Article 15), rectification (Article 16), erasure (Article 17), restriction of Processing (Article 18), data portability (Article 20), and objection (Article 21).

Because the Customer is the Controller of data about the person a request concerns, requests from that person are directed to the Customer. RunPayway™ assists the Customer in responding.

Requests may be submitted through the RunPayway™ privacy request form or by email at privacy@peoplestar.com.

RunPayway™ will respond to a Controller’s request for assistance within 30 days.

7. Data Retention

Anything run through the public demonstration on the RunPayway™ website is not stored. No record is created and nothing is retained.

Records created inside a Customer’s workspace are retained for that Customer until the Customer or the Processor deletes them, or until the service relationship ends.

No fixed retention period is published at this stage of deployment. A Customer may agree one in writing, and may request deletion of its records at any time.

Operational logs are retained only as long as needed for service integrity.

8. International Transfers

Personal Data is Processed and stored in the United States.

For transfers outside the United States, appropriate safeguards are implemented in accordance with applicable data protection laws.

9. Breach Notification

In the event of a Personal Data breach, the Processor will notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach.

Notification will include the nature of the breach, the categories of data affected, and the measures taken to address it.

10. Governing Law

This Data Processing Agreement is governed by the laws of the State of California, United States.

For Customers subject to GDPR, the Standard Contractual Clauses are incorporated by reference.

11. Framework Alignment

RunPayway™ security and data protection practices are designed with the SOC 2 Trust Services Criteria and the ISO 27001 framework in mind.

This DPA is intended to address the Processor obligations in Article 28 of the GDPR.

Framework alignment is not certification. No independent audit has been completed. Customers will be notified as any formal audit milestone is reached.

This document is a product identity and data handling description. It is provided for information and is not legal advice.

To discuss or execute this agreement, contact us through the contact page.

RunPayway™ is a product of PeopleStar Enterprises, INC. It is financial fact verification infrastructure for organizations. This document is provided for information and does not constitute legal advice.

Contact Us for Data Protection Inquiries

For any data protection requests or concerns, please reach out through the RunPayway™ contact form or by email at privacy@peoplestar.com.

Contact Us

RunPayway™ financial proof infrastructure

The Financial Proof Network. RunPayway™ establishes a requested financial fact from authorized evidence and issues a proof that can be independently verified.

Prove what matters. Share less.

RunPayway™ provides financial proof infrastructure. It is not financial, legal, tax, or investment advice, and it is not an underwriting or lending decision. A RunPayway™ proof states what was established from authorized evidence. It is not an approval, a guarantee, or a recommendation to proceed, and a result of NOT VERIFIED is not a denial or a judgment about any person. The recipient retains full responsibility for its own decision.