Joint-Controller Arrangement
Effective August 1, 2026
D.I.T.C. LLC operating as DITC.io · www.ditc.io · Version 1.0
This page publishes the essence of the joint-controller arrangement between D.I.T.C. LLC and SENDORA INC., as required by Article 26(2) of the EU General Data Protection Regulation (GDPR) and the UK GDPR. It is referenced from section 1 of our Privacy Policy.
1. The Two Controllers
| Controller | Details |
|---|---|
| D.I.T.C. LLC (“DITC”) | Wyoming limited liability company, Filing ID 2026-001951426, 30 N Gould St Ste N, Sheridan, WY 82801, USA. Technology and infrastructure provider. Holds no financial licence and no client or merchant funds. |
| SENDORA INC. (“Sendora”) | Alberta (Canada) corporation, 200-1001 1 ST SE, Calgary, Alberta T2G 5G3, Canada. Registered Money Services Business with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC), MSB Registration No. C100000575. The Settlement Entity. |
The two entities cooperate under a written Technology and Infrastructure Services Agreement. DITC provides the payment gateway platform, APIs, dashboard, routing technology, onboarding and reporting tooling, and technical support to Sendora; Sendora provides all fund-holding, settlement, payout, rolling reserve, refund, and chargeback services.
2. Where Joint Control Applies
DITC and Sendora are joint controllers within the meaning of Article 26 GDPR for the following processing activities, because they jointly determine the purposes and means:
- Account opening and onboarding.
- Identity verification, including document authentication and liveness checks.
- KYC and AML compliance, including customer due diligence and ongoing monitoring.
- Transaction monitoring.
- Fraud prevention.
- Sanctions and PEP screening.
For all other processing, each party acts as a separate controller in a controller-to-controller relationship and remains individually responsible for its own processing.
3. Allocation of Responsibility
| Processing | Controller |
|---|---|
| Website operation, user accounts on www.ditc.io, platform and dashboard usage data, technical support data, marketing communications, website analytics | DITC alone |
| Fund-holding, settlement, payout and rolling reserve data; related AML, transaction-record and regulatory-reporting data processed in Sendora’s capacity as a FINTRAC-registered MSB, including records required under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) | Sendora alone |
| Onboarding, identity verification, KYC/AML, transaction monitoring, fraud prevention, sanctions screening | DITC and Sendora jointly |
Risk, underwriting, monitoring, and suspension decisions are taken by DITC as platform operator, acting also on behalf of Sendora.
4. Single Point of Contact for Data Subjects
You may exercise your rights under Articles 15 to 22 GDPR / UK GDPR against either controller, irrespective of the allocation set out above. In practice, a single point of contact is provided so that you do not need to determine which entity holds your data:
- Send any data-subject request to privacy@ditc.io.
- DITC handles requests relating to website, account, platform, support, and marketing data directly.
- Requests concerning settlement, payout, rolling reserve, or fund-holding data are forwarded by DITC to Sendora Inc. for handling. Correspondence for Sendora is routed via support@ditc.io, with DITC acting as platform intermediary.
5. Transparency and Information Duties
DITC discharges the information duties under Articles 13 and 14 GDPR for both controllers through the Privacy Policy and the Cookie Policy, which describe the categories of data, purposes, legal bases, recipients, retention periods, international transfers, and data-subject rights applicable to both entities.
6. Security and Breach Notification
Each controller implements appropriate technical and organisational measures under Article 32 GDPR for the processing it carries out. For processing covered by the joint-controller arrangement, the two controllers coordinate breach assessment, supervisory-authority notification under Article 33, and data-subject notification under Article 34.
7. International Transfers
Personal data may be transferred to DITC in the United States (Wyoming) and to Sendora in Canada (Alberta). Transfers to Canada rely on the EU adequacy decision for organisations subject to PIPEDA and the corresponding UK adequacy regulation, with EU Standard Contractual Clauses (Decision 2021/914) and the UK International Data Transfer Addendum as a fallback. Transfers to the United States rely on the Standard Contractual Clauses and the UK Addendum, supported by a Transfer Impact Assessment and supplementary measures. Full detail is in section 6 of the Privacy Policy.
8. Supervisory Authorities
You have the right to lodge a complaint with a supervisory authority. For EU/EEA residents, the data-protection authority of your country of residence (directory at edpb.europa.eu). For UK residents, the Information Commissioner’s Office (ico.org.uk). In respect of processing carried out by Sendora Inc. in Canada, the Office of the Privacy Commissioner of Canada.
9. Availability of the Arrangement
This page sets out the essence of the arrangement as required by Article 26(2) GDPR. The underlying agreement is made available to competent regulators on request and, on reasoned request, to a data subject to the extent necessary to verify the parties’ respective roles. Requests: privacy@ditc.io.