Skip to main content
NewChargeback Protection + Fee Intelligence for high-volume merchants. Get a savings analysis and a review of your dispute handling.See how it works
Details

Chargeback Protection + Fee Optimization

See how it works: high-volume merchants get automated dispute evidence, interchange optimization, and real-time savings visibility.

See how it works

This addendum sets out how RapidCents handles personal information when it processes it in connection with the Services, and how responsibility for that information is divided between RapidCents and the merchant. The division is not the same for every activity: RapidCents is a processor for what it does on a merchant’s instruction and a controller for what it must do on its own account. Clause 4 sets out which is which, because that question decides who answers to the individual, who can be instructed to stop, and who carries the obligation when the two are not the same party.

Part 1 — Scope, definitions and roles

1. What this addendum is, and what it applies to

This is the document your privacy officer or your security reviewer asks for. It says what we do with personal information when we are handling it for you, what you have to do, and what we do on our own account because the law makes us.

This Data Processing Addendum (the “Addendum”) sets out the terms on which RapidCents Inc. (“RapidCents”) processes personal information in connection with the Services, and how responsibility for that information is divided between RapidCents and the merchant. It forms part of the RapidCents Services Agreement (the “Services Agreement”) and is addressed to the person who has to review it: a privacy officer, a security reviewer, or counsel asked whether the arrangement can be signed.

The Addendum applies to Customer Data, as clause D.1.1 of the Services Agreement defines it, and to any other personal information RapidCents processes in connection with the Services. It applies to every merchant with a RapidCents account, in Canada and in the United States, and no separate signature is required for it to bind RapidCents — clause 19 explains why.

It does not apply to the merchant’s own website, premises, systems or staff, or to what the merchant does with information it collects from its Customers outside the Services. It does not apply to a third-party service the merchant chooses to connect, which is governed by that provider’s own terms, as section 1 of the Privacy Policy states.

This is not a European Union document. RapidCents’ own processing is governed by Canadian federal and provincial privacy legislation and, for individuals in the United States, by applicable state privacy legislation. Clause D.1.2(d) of the Services Agreement places responsibility for compliance with the General Data Protection Regulation and the California Consumer Privacy Act on the merchant where the merchant deals with Customers from those jurisdictions. This Addendum does not offer a transfer instrument or a set of standard contractual clauses drawn from a regime that does not bind RapidCents. Where a United States state privacy law applies to the merchant, clause 15 states what RapidCents undertakes as its processor or service provider.

2. Definitions

The terms below have the meanings given here. Where a term is defined in the Services Agreement, this Addendum uses it with the same meaning, so that a word does not change sense between the two documents; where a term is used in the Privacy Policy, it is used here in the same sense as well.

  • “Services Agreement” means the RapidCents Services Agreement published at /legal/terms, including every policy and document incorporated into it by reference. “Services”, “Customer”, “Transaction”, “Secondary User”, “Acquirer” and “Associations” each have the meaning that agreement gives them.
  • “Customer Data” has the meaning given in clause D.1.1 of the Services Agreement: personal information or data relating to the merchant’s Customers that is collected, processed or stored in connection with the Services, including names, addresses, email addresses, telephone numbers, payment card information, bank account details, purchase histories and other transaction-related information.
  • “Cardholder Data” has the meaning given in the Services Agreement: the account number, expiry date, cardholder name and service code of a payment card, together with authentication data such as a card verification value or PIN. Section 2 of the Security Statement states which of those elements are stored and which are never stored at all.
  • “Transaction Data” has the meaning given in clause D.3.1 of the Services Agreement: data relating to Transactions processed through the Services.
  • “Personal information” means information about an identifiable individual, which is the term Canadian privacy legislation uses. Where this Addendum says “personal data” it means the same thing.
  • “Controller” means the party that decides the purposes and the means of a processing activity and answers for it. “Processor” means a party that processes personal information on a controller’s behalf, on its instructions, and decides nothing about it for itself. Both words appear here because they are the words a reviewer looks for; clauses 13 to 15 give the terms the applicable statutes actually use.
  • “Subprocessor” means a third party RapidCents engages to process Customer Data as part of providing the Services.
  • “Data subject request” means a request by an individual to exercise a right applicable privacy legislation gives them over their own personal information — access, correction, deletion, portability, withdrawal of consent, de-indexing — as section 8 of the Privacy Policy describes.
  • “Incident” covers both a breach of security safeguards, the term PIPEDA uses, and a confidentiality incident, the term Quebec’s Law 25 uses for unauthorized access to, use of or communication of personal information, its loss, or any other breach in its protection.

3. How this addendum fits the Services Agreement

This is part of your merchant agreement, not a separate contract. If the two ever disagree, the merchant agreement wins. If this and the privacy policy read differently, this document settles what we owe you and the privacy policy settles what we tell the individual. Nothing here takes away a right the privacy law gives a person.

This Addendum forms part of the Services Agreement and does not replace it. It is written to be read together with Section D of that agreement, which it explains and applies rather than amends.

Where a term of this Addendum and a term of the Services Agreement conflict and cannot be read together, the Services Agreement governs. Clause 4 sets out how two clauses of Section D that would otherwise appear to conflict with one another — D.1.1 and D.3.1 — are read together, which is why that tie-break is not reached in the one place a reader is likeliest to look for it.

Where this Addendum and the Privacy Policy describe the same processing differently, this Addendum governs as between RapidCents and the merchant, and the Privacy Policy governs what RapidCents tells the individual and what the individual may rely on. The test is who is being addressed, not which of the two roles the processing falls under: the role is the question clause 4 exists to answer, so a tie-break that turned on it would decide nothing in the one case where the two documents actually differ. Where this Addendum and the Security Statement describe the same control differently, the Security Statement governs, because it is the operative description of the controls and this Addendum deliberately does not restate them, as clause 9 explains.

The disclaimer of warranties at clause E.4, the limitation of liability at clause E.5, the indemnity at clause E.6, the arbitration agreement at clause E.7 and the individual-proceedings provision at clause H.10 apply to this Addendum as they apply to the rest of the Services Agreement. This Addendum does not create a separate liability cap and does not raise or lower the one at clause E.5.

Nothing in this Addendum limits a right an individual has under applicable privacy legislation, and nothing in it is a waiver of an obligation either party owes under that legislation.

4. The two roles, divided by activity

For anything we do because you told us to, you are in charge and we act for you. For the things we do on our own account — verifying who you are, screening sanctions, reporting to FINTRAC, managing our own fraud and credit risk, answering the card networks — we are in charge, because those are ours to decide on and to answer for rather than yours, and several of them are obligations the law puts on us directly that you could not instruct us out of. The merchant agreement now says the same thing: clause D.1.1 carries the division and points here for the detail, so this is your agreement rather than a promise standing beside it.

Clause D.1.1 of the Services Agreement states that the merchant is the data controller for Customer Data and that RapidCents acts as a data processor on the merchant’s behalf, except for the activities RapidCents carries out on its own account, for which it acts as a controller and which this clause identifies. Clause D.3.1 of the same agreement lists six purposes for which RapidCents may collect, use and share Transaction Data. The first, at D.3.1(a), is processing payments and providing the Services. The other five are detecting and preventing fraud, security breaches and other harmful activity; conducting risk assessment and underwriting; analysing usage patterns and improving the Services; complying with legal obligations including anti-money-laundering and know-your-customer requirements; and aggregating and anonymizing data for industry benchmarking, analytics and research.

Without that exception the two clauses would not describe the same relationship, which is why the exception is there. A clause stating only that RapidCents processes on the merchant’s instruction describes processing carried out for the merchant and for nothing else. D.3.1 describes that same processing at D.3.1(a), and then five further purposes RapidCents decides on and carries out for itself, some of which it is legally obliged to carry out and none of which a merchant could lawfully instruct it to stop. The exception in D.1.1 is what lets the two be read together, and this clause is where the division it refers to is set out in full.

This Addendum reads the two together by dividing the roles according to the activity rather than according to the data. A single record — a transaction record, for example — can be processed by RapidCents in both capacities at different moments and for different reasons, and it is the reason for the processing, not the field it sits in, that fixes the role. Section 3 of the Privacy Policy starts from a different question — whose information is it — and on its own that question would put everything about a merchant’s Customers on the processor side. It does not, because section 3 carries the same carve-out: several of the controller activities listed below reach a Customer’s information, and section 3 says so and points here. Read together, this clause is the fuller statement of the division and section 3 is the statement addressed to the individual, which is the order clause 3 sets.

The division is as follows. RapidCents acts as a processor, on the merchant’s documented instructions and for no purpose of its own, for the activities marked “Processor” below; it acts as a controller, on its own account and not on the merchant’s instruction, for those marked “Controller”:

  • Processor. Authorizing, routing, capturing, settling and reconciling a Transaction the merchant submits, and applying a refund, void or credit the merchant instructs.
  • Processor. Storing a payment credential as a token in the card vault where the merchant has asked for that credential to be kept for a later charge, and charging it when the merchant instructs.
  • Processor. Producing invoices, payment links, recurring billing schedules and receipts from the content the merchant supplies, and presenting hosted checkout, payment pages and terminal prompts to the merchant’s Customers in the configuration the merchant selects.
  • Processor. Compiling the merchant’s own reporting, statements, exports and dashboard views of its Customer Data.
  • Processor. Operating the risk tools the merchant has configured to act automatically on its behalf, which clause H.8 of the Services Agreement states act on the merchant’s instruction and for whose settings and outcomes the merchant is responsible.
  • Processor. Retaining, restricting, correcting, returning or deleting Customer Data at the merchant’s direction, subject to clause 18.
  • Controller. Verifying the identity of the merchant, its directors and its beneficial owners, and screening them and the parties to a Transaction against the sanctions lists named in clause H.3 of the Services Agreement. Clause 13 sets out the registrations that make this RapidCents’ own obligation.
  • Controller. Transaction monitoring, suspicious transaction reporting, and any other report RapidCents is required or permitted to make to a regulator or a law enforcement authority — which clause H.3 records RapidCents may be prohibited by law from telling the merchant it has made.
  • Controller. RapidCents’ own fraud prevention, risk scoring, underwriting, reserve and payout decisions, and the controls clause H.8 describes as operated for RapidCents’ own account and in the interests of the Acquirer, the Associations and other merchants rather than for the merchant’s benefit.
  • Controller. Reporting to and responding to the Acquirer, the Associations and RapidCents’ regulators, including chargeback and representment handling, fines and assessments, and the forensic investigation process at clause D.2.3.
  • Controller. Meeting RapidCents’ own record-keeping, tax, audit and PCI DSS obligations, defending its own legal claims, and operating and securing the platform itself, as the Security Statement describes.
  • Controller. Administering the merchant relationship: onboarding, support, billing, collections and the communications described at clause D.3.2 of the Services Agreement.
  • Controller. Analysing usage patterns to improve the Services under clause D.3.1(d), and producing aggregated and anonymized benchmarking, analytics and research under clause D.3.1(f).

The distinction is not a drafting convenience. Where RapidCents is a controller it cannot accept an instruction from the merchant to stop, it answers to the individual and to the regulator itself, and the merchant is not made answerable for what RapidCents decides. Where RapidCents is a processor it may decide nothing for itself, and the merchant remains the party the individual deals with. Clause H.8 of the Services Agreement states the same division on the operational side: a risk tool the merchant configures acts on the merchant’s instruction, while the risk, fraud, sanctions and compliance controls RapidCents operates for its own account are expressly not operated for the merchant’s benefit.

A reviewer is entitled to know what standing this clause has. Clause D.1.1 carries the same division and refers to this clause for it, so the two are read together and the tie-break in clause 3 — under which the Services Agreement would govern a conflict that cannot be resolved by reading — is not reached. RapidCents gives the division as an undertaking to the merchant as well, which is what puts it in the merchant’s hands rather than leaving it as a description: RapidCents does not rely on clause D.1.1 to disclaim the controller obligations described above, and does not rely on this clause to reduce the processor obligations clause D.1.3 imposes.

5. The particulars of the processing

This is the table a reviewer turns to first: what we process, why, for how long, about whom, and which fields.

The tables below set out the particulars of the processing RapidCents carries out as the merchant’s processor under clause 4. They describe the Services as RapidCents provides them; what actually occurs for a given merchant depends on which of the Services that merchant uses and how it has configured them.

Particulars of the processing RapidCents carries out as processor
Particular What applies
Subject matter Provision of the Services to the merchant under the Services Agreement: accepting, authorizing, routing, capturing, settling, reconciling, refunding and reporting the payments the merchant takes from its Customers, and the merchant’s use of the dashboard, virtual terminal, hosted checkout, payment links, invoicing, recurring billing, point-of-sale software, terminals, APIs and SDKs.
Duration For the term of the Services Agreement, which clause F.1.1 sets at an initial term of four (4) years renewing for successive one (1) year periods, and after termination only for as long as clause 18 and the retention the law independently requires allow. This Addendum has no separate term.
Nature of the processing Collection, recording, organization, structuring, storage, tokenization, retrieval, consultation, use, transmission to and from the Acquirer and the Associations, disclosure to the recipients listed in section 6 of the Privacy Policy, restriction, erasure and destruction, carried out by automated means.
Purpose of the processing Providing the Services on the merchant’s documented instructions, as clause D.1.3(a) requires and as clause 7 defines those instructions. No other purpose. Processing RapidCents carries out for its own purposes is listed in clause 4 and is carried out as a controller, not for the merchant.
Location of the processing Canada and the United States, together with the processing country the subprocessor register published in section 9 of the Subprocessors page at /legal/subprocessors states for a provider, where it states one. Clause 12 states the cross-border position and the route for asking where the register leaves that cell blank.
Frequency Continuous for the term of the Services Agreement, and in real time for authorization and settlement.

The processing RapidCents carries out as a controller — identity verification, sanctions screening, regulatory reporting, its own fraud and risk management, network reporting and the other activities listed in clause 4 — is not covered by this table. Sections 4, 5 and 7 of the Privacy Policy describe it.

Categories of data subject and of personal data processed as processor
Category of data subject Categories of personal data
The merchant’s Customers — the cardholders and payers from whom the merchant accepts payment Name; billing address and, where the merchant collects it, shipping address; email address; telephone number; the payment card or bank account details used, held as the Security Statement describes; the billing postal code used for address verification; the transaction amount, currency, date and time; the approval or decline result and its reason; the card brand and last four digits; the token that stands in for the card credential; the order, invoice, receipt and product description the merchant submits; purchase history; the device, channel and IP address where the merchant’s integration transmits them; and correspondence about a transaction, refund or dispute.
Individuals named in the merchant’s own records submitted through the Services — for example a contact named on an invoice, a recipient named for delivery, or a person named in a support ticket Name; contact details; and whatever else the merchant chooses to record about them in the fields it completes.

The Services do not require sensitive personal information. RapidCents does not ask for and does not need health, biometric, racial or ethnic origin, political, religious, trade union, sexual life or criminal record information in order to process a payment, and a merchant should not transmit it through a free-text field. Where a merchant does so, it does so on its own instruction and remains the controller of it. Personal information about the merchant itself, its personnel, its directors and its beneficial owners is processed by RapidCents as a controller and is described in section 4 of the Privacy Policy rather than here.

Part 2 — What each party undertakes

6. The merchant’s obligations as controller

You decide what is collected and why, so you need the lawful basis or the consent, and you need to have told your customers — in your own privacy notice — that a payment processor will see their information.

Clause D.1.2 of the Services Agreement sets out what the merchant owes as controller. This clause restates it, because a merchant reviewing this Addendum should not have to hold two documents open, and states how each obligation applies under Canadian privacy legislation. It imposes no obligation the merchant has not already accepted under the Services Agreement.

  • Rights, permissions and consents. The merchant must have all necessary rights, permissions and consents to collect, process, use and share Customer Data with RapidCents and its service providers, as clause D.1.2(a) requires and as clause E.3(e) is warranted. Under Canadian privacy legislation that means a lawful basis for the collection and, where consent is that basis, a meaningful consent: the individual must reasonably understand what is collected, why, and to whom it is disclosed.
  • The merchant’s own privacy notice. The merchant must give its Customers a clear and accurate privacy notice disclosing how their information will be used, including that it is shared with RapidCents for payment processing, as clause D.1.2(b) requires. RapidCents’ Privacy Policy is not a substitute: it describes RapidCents’ processing, not the merchant’s.
  • Lawful instructions, and minimizing what is sent. The merchant must not instruct RapidCents to process Customer Data in a way that would put either party in breach of applicable privacy legislation, the Network Rules or the Acceptable Use Policy, and should not transmit personal information the Services do not need. A free-text field — an invoice line, a product description, a support ticket — is not a safe place for sensitive information, and what the merchant puts there is what the merchant has instructed RapidCents to process.
  • Its own safeguards. The merchant must implement appropriate technical and organizational measures to protect the Customer Data under its own control, as clause D.1.2(c) requires, and must meet the security obligations at clause D.2, including its own PCI DSS validation. Section 11 of the Security Statement sets out where RapidCents’ controls stop and the merchant’s begin.
  • Compliance with privacy legislation. The merchant must comply with applicable privacy and data protection legislation, including PIPEDA, provincial privacy legislation and, where it deals with Customers from those jurisdictions, the General Data Protection Regulation or the California Consumer Privacy Act, as clause D.1.2(d) requires.
  • Telling RapidCents about an incident. The merchant must promptly notify RapidCents of any actual or suspected data breach affecting Customer Data, as clause D.1.2(e) requires, and must follow clause D.2.3 where card data may be involved. Clause 16 sets out both routes.
  • Answering its own Customers. The merchant must respond to and fulfil access requests, deletion requests and other rights exercised by its Customers, as clause D.1.2(f) requires. Clause 10 sets out what RapidCents does to help.

7. RapidCents’ obligations as processor

When we are working for you, we do what you tell us and nothing else. Your instructions are the agreement, this addendum, and the settings and calls you actually make.

Clause D.1.3 of the Services Agreement sets out what RapidCents owes as processor. This clause restates those obligations and states what counts as an instruction, because “documented instructions” is the term that decides disputes and is rarely defined.

RapidCents processes Customer Data only for the purposes of providing the Services and in accordance with the Services Agreement and the merchant’s documented instructions, as clause D.1.3(a) requires. The merchant’s documented instructions are:

  • the Services Agreement, this Addendum and the other documents incorporated into the Services Agreement;
  • the configuration the merchant selects in the merchant dashboard, including its integration method, its stored-credential settings, its recurring billing schedules, its receipt and descriptor settings, and the risk tool settings clause H.8 describes as acting on the merchant’s instruction;
  • each API call, terminal transaction, virtual terminal entry, payment link, invoice and dashboard action the merchant or a Secondary User submits; and
  • any further instruction the merchant gives in writing under clause F.3 of the Services Agreement, which RapidCents will follow where it is lawful and technically feasible.

RapidCents does not process Customer Data for its own purposes in its processor capacity. It does not sell personal information, does not use cardholder transaction detail to build advertising profiles, and does not disclose one merchant’s data to another, as section 5 of the Privacy Policy states. Processing RapidCents carries out on its own account is listed in clause 4, is carried out as a controller, and is neither authorized by nor attributable to the merchant.

If RapidCents forms the view that an instruction from the merchant would breach applicable privacy legislation, it will tell the merchant rather than carry it out silently, and it may decline to act on the instruction until the point is resolved.

RapidCents will implement appropriate technical and organizational security measures to protect Customer Data, as clause D.1.3(b) requires and as clause 9 describes; will ensure that personnel authorized to process Customer Data are bound by appropriate confidentiality obligations, as clause D.1.3(e) requires and as clause 8 describes; will assist the merchant so far as reasonably possible in responding to data subject requests, as clause D.1.3(c) requires and as clause 10 describes; will notify the merchant without undue delay on becoming aware of a data breach affecting Customer Data, as clause D.1.3(d) requires and as clause 16 describes; and will return or delete Customer Data on termination except where retention is required by law, as clause D.1.3(f) requires and as clause 18 describes.

8. Confidentiality of personnel

Personnel authorized to process Customer Data are bound by appropriate confidentiality obligations, as clause D.1.3(e) of the Services Agreement requires. The confidentiality provision at clause E.2 binds each party in respect of the other’s Confidential Information, and Customer Data is treated as the merchant’s Confidential Information for that purpose.

Confidentiality is enforced by access control rather than by undertaking alone. Access is granted by role, so that a role carries the access its work requires and no more; multi-factor authentication is required for staff and is not an option a user can decline; internal systems are reached over a VPN that exposes a limited selection of systems rather than the environment as a whole; and access to merchant data by authorized RapidCents staff is logged, producing an audit trail that can be reviewed after the fact. Sections 2 and 4 of the Security Statement describe those controls.

A person who does not need Customer Data for the task in front of them is not given access to it. Data belonging to different merchants is logically separated and is not accessible between merchants, as section 2 of the Security Statement states.

9. Security measures

We are not going to describe our security twice. The Security Statement is the description; this addendum points at it so the two cannot drift apart.

RapidCents implements appropriate technical and organizational security measures to protect Customer Data, as clause D.1.3(b) of the Services Agreement requires. Those measures are described in the Security Statement, which is incorporated into this Addendum by reference and is the operative description of them.

This Addendum does not restate the controls. A second description in a second document is a description that will fall out of step with the first, and a merchant relying on the stale one is relying on something that is no longer true. The Security Statement covers how card data is handled and what is never stored at all, encryption in transit and at rest, access control and authentication, network and infrastructure security, monitoring and intrusion detection, secure development and change control, testing and independent assessment, and backup and continuity.

Two points bear directly on the merchant’s own assessment and are worth stating here. RapidCents is a PCI DSS Level 1 service provider, and clause D.2.1 requires both parties to comply with PCI DSS when handling Cardholder Data. And the controls described in the Security Statement cover the RapidCents platform: they do not extend to the merchant’s networks, devices, staff or software, and they do not discharge the merchant’s own PCI DSS obligations, as section 11 of the Security Statement and clauses D.2.1(a) and D.2.2 make plain.

Where a reviewer needs evidence rather than a description, clause 17 sets out how it is obtained.

10. Assisting with requests from individuals

Your customer asks you, not us. If they come to us, we point them back to you and tell you they did. Most of what they can ask for, you can do yourself in the dashboard.

A Customer’s request about information the merchant controls is the merchant’s to answer, as clause D.1.2(f) of the Services Agreement provides and as section 3 of the Privacy Policy explains to the individual. RapidCents assists; it does not answer on the merchant’s behalf.

Assistance takes three forms, in this order:

  • The dashboard first. Most requests can be met by the merchant without involving RapidCents: the merchant can retrieve and export the transaction, invoice and customer records it holds, correct a record it maintains, and delete a customer record — which removes the stored payment credential held as a token in the card vault, as section 7 of the Privacy Policy states.
  • Then a request to RapidCents. Where the request cannot be met from the dashboard, RapidCents assists the merchant so far as reasonably possible, as clause D.1.3(c) requires. Requests go to the Privacy Officer at the address in clause 19, or in writing to [email protected]. RapidCents will respond in time for the merchant to meet its own statutory deadline where the merchant tells it what that deadline is, so a request should be forwarded promptly rather than at the end of the merchant’s own response period.
  • A request that reaches RapidCents directly. Where an individual contacts RapidCents about information RapidCents processes for a merchant, RapidCents tells the individual to contact the merchant, as section 12 of the Privacy Policy directs, and informs the merchant of the request. RapidCents will not disclose, correct or delete that information on the individual’s instruction alone, because it is not RapidCents’ decision to make.

Two limits apply, and both are real rather than defensive. RapidCents may verify who is asking before disclosing anything, so that personal information is not disclosed to someone else; and a deletion request cannot reach information RapidCents is independently required to retain, which clause 18 describes.

Where the request concerns processing RapidCents carries out as a controller — the activities listed in clause 4 — the individual deals with RapidCents directly, and section 8 of the Privacy Policy sets out the rights that apply and the commitment to respond within thirty (30) days.

11. Subprocessors

We use other companies to run parts of the service. The Subprocessors page publishes what kinds of company they are and what each can reach, and section 9 of it publishes the register that names them and says what each does. That register is not the whole supply chain, and the current full list is yours to obtain by the route that page gives. They are bound to the same standard we are, and we stay answerable to you for them.

The merchant authorizes RapidCents to engage Subprocessors to process Customer Data as part of providing the Services. Clause D.1.2(a) of the Services Agreement contemplates this, by requiring the merchant to hold the rights, permissions and consents necessary to share Customer Data with RapidCents and its service providers.

The Subprocessors page at /legal/subprocessors is the authoritative statement of the categories RapidCents engages, what each category can reach, and the commitments made about every subprocessor before it is engaged. The names are held in a maintained register, which states for each provider its category, what it is engaged to do and, where the register states one, the country in which it processes. Section 9 of that page publishes the register, states that it is complete as to the parties it names and that it is not the whole supply chain, carries the date it was last reviewed together with the undertaking RapidCents gives about reviewing it, and sets out the routes by which the current full list is obtained — in whatever form a review needs, including as an appendix to this Addendum. This Addendum restates neither the categories nor the register, so that the two cannot fall out of step.

Every service provider that handles personal information for RapidCents is bound by contract to use it solely for the service it provides to RapidCents, to protect it, and to return or delete it when the engagement ends, as section 6 of the Privacy Policy states. RapidCents assesses the privacy implications before entrusting personal information to a provider in another jurisdiction, as clause 12 describes. RapidCents remains responsible to the merchant for a Subprocessor’s processing of Customer Data as it is for its own.

The Acquirer, the Associations and the issuing banks are not Subprocessors. They receive Transaction Data as participants in the payment system rather than as service providers acting on RapidCents’ instructions, and they handle it under their own rules, including the Visa and Mastercard operating regulations, as section 6 of the Privacy Policy states. RapidCents does not control their processing and does not undertake for it. Section 9 of the Subprocessors page names them all the same, in a table set apart from the register and labelled with their own role, because a merchant asking who receives its data is asking about the payment path rather than about a classification. The same is true of a third-party integration the merchant chooses to connect, which is governed by that provider’s own terms.

Notice of a change, and what a merchant can do if it objects, are governed by section 10 of the Subprocessors page and are adopted into this Addendum rather than restated differently here: thirty (30) days’ notice before a change that materially affects how personal information is handled, an objection made in writing to the Privacy Officer or to [email protected], the complaint procedure at clause A.6 of the Services Agreement where the objection is not resolved, and the freedom to close the account — with no early termination fee and no cancellation penalty of any kind, as clauses A.4 and F.1.2 provide. RapidCents has not set a separate objection window, and this Addendum does not state one it does not have; the thirty (30) day notice period is the period in which to object.

Part 3 — Location, applicable law and transfers

12. Where processing happens, and transfers across a border

We operate in Canada and the United States and use cloud providers, so your customers’ information may be processed outside the province or the country they live in. When it is, that country’s courts and authorities can reach it. We do not pretend otherwise.

RapidCents operates in Canada and the United States and uses cloud infrastructure and service providers that may store or process personal information outside the province or the country where an individual lives, including in the United States. Where that happens, the information is subject to the laws of that jurisdiction and may be accessible to its courts, its law enforcement and its national security authorities. Section 9 of the Privacy Policy states the same position to the individual.

RapidCents transfers personal information only to providers bound by contract to protect it to a standard comparable to the one RapidCents applies. That is what the accountability principle under PIPEDA requires of an organization transferring personal information to a third party for processing: the information remains under the transferring organization’s control, and contractual or other means must be used to give it a comparable level of protection while it is being processed.

Before entrusting personal information to a provider outside Quebec, RapidCents conducts the privacy impact assessment Quebec’s Law 25 requires, as clause 14 describes. Where a merchant needs to know the country in which a particular category of its data is processed, the subprocessor register published in section 9 of the Subprocessors page states the country for each provider it records one for, and leaves it visibly blank where it does not rather than supplying a country by inference. The country for a provider the register leaves blank is asked for, like the current full list itself, by the routes that section sets out.

RapidCents does not publish a standard contractual clause set, a binding corporate rule, or an adequacy-based transfer instrument drawn from a privacy regime that does not bind it, and this Addendum does not incorporate one. A merchant whose own obligations require a specific transfer instrument should raise it in writing at [email protected] before relying on this Addendum.

13. Canada: PIPEDA and the provincial private-sector Acts

This is the Canadian clause; clause 15 is the United States one, and a merchant can be subject to both for different people. PIPEDA is the federal law that applies to us, and Alberta, British Columbia and Quebec have their own. Two things follow for you: we stay accountable for information we hand to a supplier, and we have to report a breach to the Privacy Commissioner and tell the people affected where it could really harm them. Our FINTRAC and Bank of Canada registrations are ours and not yours, which is why the checks they require sit on our side of clause 4.

This clause states the position under Canadian privacy legislation. It applies to a merchant carrying on business in Canada, to processing carried out in Canada, and to personal information about individuals in Canada. Clause 15 states the position under United States state privacy legislation. The two are not alternatives: a merchant may be subject to both, for different individuals.

RapidCents is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA). Where a province has substantially similar legislation — Quebec, Alberta and British Columbia — that legislation applies to activity within it: the Personal Information Protection Act in Alberta and in British Columbia, and the Act respecting the protection of personal information in the private sector, as amended by Law 25, in Quebec. Section 2 of the Privacy Policy states the same.

Three consequences of PIPEDA bear directly on this Addendum. Accountability: an organization remains accountable for personal information it transfers to a third party for processing and must use contractual or other means to provide a comparable level of protection, which clauses 11 and 12 record. Limiting use and disclosure: personal information may be used or disclosed only for the purpose it was collected for, unless the individual consents or the law requires or permits otherwise, which is why RapidCents’ processor processing is confined to the instructions defined in clause 7 and its controller processing is listed and justified in clause 4. Safeguards and breach reporting: an organization must protect personal information with safeguards appropriate to its sensitivity, must report a breach of security safeguards to the Office of the Privacy Commissioner of Canada and notify affected individuals where it creates a real risk of significant harm, and must keep a record of every such breach. Clauses 9 and 16 address those.

The Alberta and British Columbia Acts impose materially similar obligations of consent, limited use, safeguarding and accountability on organizations carrying on activities within those provinces, and Alberta additionally requires notification to its Commissioner where a loss of or unauthorized access to personal information creates a real risk of significant harm.

RapidCents is registered with the Bank of Canada as a payment service provider under the Retail Payment Activities Act and with the Financial Transactions and Reports Analysis Centre of Canada as a money services business under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, as clause H.3 of the Services Agreement records. The identification, record-keeping, monitoring, sanctions-screening and reporting obligations those registrations carry are RapidCents’ own. They are the clearest illustration of the controller processing described in clause 4, and no instruction from a merchant can displace them. RapidCents also adheres to the principles of the Code of Conduct for the Credit and Debit Card Industry in Canada, as clause A.9 provides.

14. Quebec: Law 25

If you do business in Quebec, or your customer is in Quebec, Law 25 applies on top. It requires this document to exist in writing, it requires an assessment before information leaves the province, and it gives people extra rights.

Where the merchant carries on an enterprise in Quebec, or where an individual whose personal information is processed is in Quebec, the Act respecting the protection of personal information in the private sector, as amended by Law 25, applies in addition to what clause 13 describes.

Law 25 requires that where personal information is communicated to a person or body outside the enterprise in the course of performing a mandate or a service contract, the mandate or contract be in writing, and that it set out the measures the person must take to protect the confidentiality of the information, to use it only for carrying out the mandate, and not to keep it once the mandate is complete. This Addendum, together with clause D.1.3 of the Services Agreement and the Security Statement, is that writing: clause 7 confines the use, clauses 8 and 9 state the confidentiality and security measures, and clause 18 states what happens at the end.

Law 25 also requires a privacy impact assessment before personal information is communicated outside Quebec, taking account of the sensitivity of the information, the purposes for which it is to be used, the protection measures it would carry, and the legal framework of the jurisdiction it would be communicated to. RapidCents conducts that assessment before entrusting personal information to a provider in another jurisdiction, as section 9 of the Privacy Policy states, and a merchant may ask the Privacy Officer about RapidCents’ practices in this area.

Where a confidentiality incident presents a risk of serious injury, RapidCents notifies the affected individuals and the Commission d’accès à l’information as the law requires, and it keeps a register of confidentiality incidents, as section 10 of the Privacy Policy states. Clause 16 sets out how notification works between RapidCents and the merchant.

Law 25 gives individuals in Quebec rights in addition to those described in clause 10, including the right to be informed when a decision about them is made exclusively by automated processing and to submit observations on it, and the right to have information de-indexed in the circumstances the Act provides. Section 8 of the Privacy Policy records both. Where the automated decision is one the merchant has configured — a risk tool acting on the merchant’s instruction under clause H.8 — the merchant is the party that must inform the individual and receive the observations; where it is a decision RapidCents makes on its own account, RapidCents is.

15. United States: state privacy legislation

If a US state privacy law applies to you, this is the clause your counsel reads. For the work we do on your instruction we are your processor or service provider: we do not sell your customers’ information, we do not share it for cross-context advertising, and we help you answer the requests your customers make. For the work we do on our own account we answer to the individual ourselves. Which state exemptions your business can claim is a question for your counsel and not for us.

This clause states the position under United States state privacy legislation. It applies where a merchant is subject to a comprehensive state privacy law in respect of a given individual — most of those laws use the terms controller and processor, and California uses business and service provider — and it applies in addition to clause 13, not instead of it, where both are engaged.

For the processing listed in clause 4 as processor processing, RapidCents acts as the merchant’s processor or service provider and, on that footing:

  • processes personal information only for the business purposes specified in the Services Agreement and this Addendum, and on the merchant’s documented instructions as clause 7 defines them;
  • does not sell personal information and does not share it for cross-context behavioural advertising. RapidCents does not sell personal information as that term is defined in those laws, as section 2 of the Privacy Policy states;
  • does not retain, use or disclose personal information outside the direct business relationship between RapidCents and the merchant, or for any purpose other than performing the Services, except where the law requires or permits it;
  • does not combine personal information received from the merchant with personal information received from another source, except as those laws permit — which includes what is necessary to detect security incidents and to prevent, detect and investigate fraud, and which is why the controller processing in clause 4 is described there rather than presented as processing carried out for the merchant;
  • assists the merchant in responding to consumer requests to know, delete, correct, opt out and appeal, as clause 10 describes; and
  • will tell the merchant if it determines that it can no longer meet its obligations under the applicable state law.

Where RapidCents processes personal information as a controller or business in its own right — the activities listed in clause 4 — it answers to the individual directly for that processing, and section 8 of the Privacy Policy describes the rights available and the appeal route that applies.

Some of what RapidCents does is regulated by United States federal legislation directed at financial institutions and payment activity, including the Gramm-Leach-Bliley Act, as well as by state privacy legislation, and several state privacy laws exempt information or entities regulated under that federal legislation. This Addendum does not attempt to allocate those exemptions. Which of them applies to a given merchant depends on that merchant’s own status, and that is a determination for the merchant’s counsel rather than for RapidCents.

Part 4 — Incidents, audit and the end of the relationship

16. Incidents affecting personal information

If something happens on our side, we tell you without undue delay, and we tell you what we know and what we do not yet know. We are not going to promise you a number of hours that no other RapidCents document supports.

RapidCents notifies the merchant without undue delay on becoming aware of a data breach affecting Customer Data, as clause D.1.3(d) of the Services Agreement requires. Section 10 of the Security Statement states the same commitment operationally: where an incident affects a merchant’s data or account, RapidCents notifies the affected merchants without undue delay and states what is known, what is not yet established, and what the merchant should do.

This Addendum does not state a fixed number of hours for that notification. Neither the Services Agreement nor the Security Statement fixes one, and a figure introduced here would be a commitment the rest of RapidCents’ documentation does not carry. “Without undue delay” means as soon as RapidCents is able to give the merchant something it can act on. It does not permit RapidCents to wait until an investigation is complete: a first notice that says plainly what is not yet known is the expected form.

A notification will describe, so far as it is then known: the nature of the incident; the categories and approximate number of individuals and of records affected; the likely consequences; the measures taken or proposed to address the incident and mitigate its effects; and a contact point for further information. Where that detail is not available at the time of the first notice, it is provided as it becomes available.

The obligation runs the other way as well. The merchant must promptly notify RapidCents of any actual or suspected data breach affecting Customer Data, as clause D.1.2(e) requires. Where card data may be involved, clause D.2.3 requires the merchant to notify RapidCents immediately of any suspected, alleged or confirmed Compromised Data Event, regardless of its source and including one affecting the merchant’s own third-party service providers, by emailing both [email protected] and [email protected]. That obligation is immediate, and no RapidCents document converts it into an outer limit expressed in hours: section 10 of the Security Statement states the same requirement in the same terms. Clause D.2.3 also requires the merchant not to alter or destroy related records, to cooperate fully with a forensic vendor approved by an Association, and to bear the costs of the investigation.

Notification to a regulator follows the role. RapidCents makes the reports it is required to make as a controller, including to the Office of the Privacy Commissioner of Canada under PIPEDA and to the Commission d’accès à l’information under Law 25, and to the Acquirer and the Associations as law and the Network Rules require; it keeps the record of breaches PIPEDA requires and the register of confidentiality incidents Law 25 requires, as section 10 of the Privacy Policy states. Where the merchant is the controller of the affected information, the decision to notify its Customers and its own regulators is the merchant’s and is the merchant’s to make on time. RapidCents provides the information the merchant reasonably needs in order to make it.

Notification of an incident is not an admission by either party that it caused the incident or that it failed in an obligation.

17. Audit rights, and how they are satisfied

Read the published material first — the security page, the PCI page, the subprocessors page and the Trust Centre. Most reviews end there. An on-site audit is the last resort, not the opening request.

A merchant is entitled to satisfy itself that RapidCents is meeting the obligations in this Addendum. RapidCents meets that entitlement in a defined order, and the order matters: an on-site audit of a payment platform is disruptive, is of limited value to the merchant compared with an independent assessment, and cannot be given to every merchant at once.

  • Independent attestation first. RapidCents is a PCI DSS Level 1 service provider. Maintaining that status involves on-site audits, vulnerability scanning, external scanning by Approved Scanning Vendors and penetration testing against the Payment Card Industry Data Security Standard, as section 8 of the Security Statement records; penetration testing is carried out by the RapidCents security team and by third-party professionals. Section 8 of the PCI Compliance page explains how to request RapidCents’ Attestation of Compliance.
  • Then the published material. The Security Statement, the PCI Compliance page, this Addendum and the Subprocessors page are published so that a review can begin without waiting on a response. The Trust Centre at /company/trust carries the security and diligence material a procurement or security review works through.
  • Then a written request. Where the published material and the attestation genuinely do not answer the question, the merchant may make a reasonable written request for further information about the processing carried out under this Addendum, addressed to [email protected] under clause F.3 of the Services Agreement. RapidCents will respond to a reasonable request.
  • An inspection last. Where applicable privacy legislation or a regulator requires the merchant to carry out an inspection that the steps above cannot satisfy, RapidCents will accommodate one on the conditions set out below.

An inspection under this clause is arranged in writing in advance and conducted at a time that does not disrupt the operation of the Services. It is limited to the systems, controls and records that carry the merchant’s own Customer Data. It may not extend to another merchant’s data, to personal information about another merchant’s Customers, to RapidCents’ own Confidential Information, or to anything RapidCents is prohibited from disclosing by the Network Rules, by a regulator or by law. The auditor must be independent, must not be a competitor of RapidCents, and is bound by the confidentiality provision at clause E.2 of the Services Agreement; RapidCents may require the auditor to sign a confidentiality undertaking before access is given.

How the cost of such an inspection is borne is agreed in writing when the inspection is arranged. This Addendum does not fix it, because no RapidCents document fixes it and stating a figure here would create a charge that does not exist.

This clause runs in the merchant’s favour only. Clause H.4 of the Services Agreement gives RapidCents, the Acquirer, an Association and a regulator a separate and independent right to require records, production and an audit from the merchant, and nothing in this clause limits it.

18. Return or deletion of Customer Data when the relationship ends

Export what you need before you close the account. We will delete the rest — except the records the law makes a payment processor keep, which we cannot delete for you and will not pretend we can. Closing an account costs nothing.

On termination of the Services, RapidCents returns or deletes Customer Data in accordance with the Services Agreement, except where retention is required by law, as clause D.1.3(f) provides.

Return comes first, and it is largely in the merchant’s hands. The merchant can export its transaction, settlement, invoice and customer records from the merchant dashboard while it still has access, and it should do so before that access ends: clause F.1.4 provides that on termination the merchant ceases using the Services and every licence granted to it terminates. Where an export is needed after that point, the merchant may request it in writing under clause F.3, and RapidCents will provide the Customer Data it then holds in a commonly used format.

Deletion follows, and this is where an honest document has to qualify itself. RapidCents is a payment processor, a registered payment service provider and a registered money services business, and a substantial part of what it holds is a record it is independently required to keep. It cannot delete that record on the merchant’s instruction, and this Addendum does not promise that it will.

  • Identity verification and onboarding records are retained for the period required of a reporting entity under Canadian anti-money-laundering legislation, which runs from the end of the business relationship, as section 7 of the Privacy Policy states.
  • Transaction and settlement records are retained for the period required for tax, audit and Card Network dispute purposes.
  • A record relating to a Transaction that is the subject of a chargeback, a dispute, an investigation, an audit or a legal proceeding is retained until that matter is finally resolved, which is the same rule clause H.4 of the Services Agreement imposes on the merchant.
  • Cardholder data, where it is retained at all, is held for up to 24 months of inactivity, as section 2 of the Security Statement states. Card verification values, PINs, EMV chip data and magnetic-stripe data are not stored at any point and so are not part of this exercise.
  • Marketing preferences and opt-outs are retained indefinitely, because a record of an opt-out is what makes it possible to honour it.
  • Data held in backups is removed on the ordinary rotation of those backups rather than on the day a deletion is executed. Databases are backed up daily, between data centres and offsite, as section 9 of the Security Statement states. Data that remains in a backup is subject to the same controls and is not returned to active use.

Data retained under this clause is processed only for the purpose that requires it to be retained. It is not used to provide the Services to anyone else, is not used for RapidCents’ marketing, and remains protected by the controls described in the Security Statement for as long as it is held. Section 7 of the Privacy Policy sets out the retention position in full.

Aggregated and anonymized data produced under clause D.3.1(f) is not returned or deleted under this clause, because once it no longer identifies any individual it is no longer personal information. That is a statement about what the data has become, not a route around deletion: information that can still be re-identified is still personal information and is treated as such.

Closing an account costs nothing. Clause F.1.2 provides that the merchant may terminate at any time by written notice, that RapidCents charges no early termination fee, and that it imposes no penalty for closing an account before the end of the Initial Term or a Renewal Term. This Addendum introduces no charge of any kind for the return or deletion of Customer Data.

Termination does not end everything. Clause F.1.4 provides that RapidCents may withhold funds or establish a Reserve for a reasonable period against potential chargebacks, refunds, fees and fines, and that the merchant remains liable for obligations relating to Transactions processed before termination. The obligations in this Addendum that relate to retained Customer Data survive for as long as RapidCents holds it.

19. Changes to this addendum, notices and contact

Clause D.1.4 of the Services Agreement incorporates the Privacy Policy into that agreement, and section 3 of the Privacy Policy states that this Addendum sets out the commitments governing RapidCents’ processor role. This Addendum therefore applies to every merchant and binds RapidCents without a separate signature. A merchant whose own procurement process requires a signed counterpart should write to [email protected].

RapidCents may revise this Addendum. The effective date and the date last revised appear at the head of this page and are not the same thing: the revision date changes with every edit, the effective date only when the substance of the commitments changes. Clause F.2 of the Services Agreement governs amendment of the agreement as a whole. Where a change materially affects how RapidCents handles personal information, notice is given at least thirty (30) days before it takes effect, by email or through the merchant dashboard, as section 14 of the Privacy Policy provides.

Notices to RapidCents under this Addendum are given in writing to [email protected], or by mail with return receipt requested to RapidCents Inc., Attention: Legal Department, 515 Consumers Road, Unit 210, North York, Ontario, M2J 4Z2, as clause F.3 of the Services Agreement requires. A suspected or confirmed compromise of card data goes to both [email protected] and [email protected], as clause D.2.3 requires, and not to the legal address alone.

Privacy questions, data subject requests and complaints go to the Privacy Officer: Privacy Officer, RapidCents Inc., 515 Consumers Road, Unit 210, North York, Ontario, M2J 4Z2, Canada, telephone +1-844-957-2743. In the United States: 43300 Southern Walk Plaza, #166, Ashburn, Virginia 20148, telephone +1-202-902-6226. If RapidCents’ response does not satisfy you, section 8 of the Privacy Policy names the regulators you may complain to.

A complaint about the Services rather than about privacy follows the escalation procedure at clause A.6 of the Services Agreement, which begins with Support and escalates to the Executive Office.

Governing law

The Province of Ontario and the federal laws of Canada applicable therein, as clause E.7 of the Services Agreement provides. Disputes are determined by arbitration in Toronto, Ontario.

Questions about this document

Write to RapidCents Inc., 515 Consumers Road, Unit 210, North York, Ontario, M2J 4Z2, or call +1-844-957-2743. In the United States: 43300 Southern Walk Plaza, #166, Ashburn, Virginia 20148, or call +1-202-902-6226.