Subprocessors
- Effective
- Last updated
A subprocessor is a company RapidCents engages to perform part of the Services, and which in doing that work handles personal information RapidCents holds — including personal information a merchant is responsible for. This page explains what a subprocessor is and how it differs from a supplier you engage yourself, the categories RapidCents engages and what each can reach, the commitments made about every subprocessor before it is engaged, what it means that some processing occurs outside Canada, the register naming the providers RapidCents engages and how to obtain the current full list, and what you can do if you object to a change.
1. What a subprocessor is
No payment platform runs entirely on its own machines. A subprocessor is a company we engage that ends up handling data you are responsible for.
RapidCents does not perform every part of the Services itself. The servers the platform runs on, the systems that carry a message to the Card Networks, the checks that verify a business at onboarding, the service that delivers an email — some of that is done by other companies RapidCents engages. Where such a company handles personal information RapidCents holds, it is a subprocessor.
The term follows from clause D.1 of the Services Agreement and section 3 of the Privacy Policy. For personal information about a merchant’s own customers — Customer Data, as D.1 defines it — the merchant is the controller and decides what is collected and why; RapidCents is the processor and handles it on the merchant’s documented instructions; a subprocessor is a company RapidCents in turn engages to perform part of that processing. Each link is bound by the one above it. That is the position for processing RapidCents carries out on the merchant’s instruction; clause 4 of the Data Processing Addendum lists the narrower set of activities — sanctions screening, regulatory reporting and RapidCents’ own fraud and risk decisions among them — that reach the same information but that RapidCents carries out as a controller, which is why section 11 says this page sits underneath both roles.
A subprocessor is not a supplier you engage yourself. An accounting package or a shopping-cart plugin you connect to your account is engaged by you: clause B.6 of the Services Agreement makes you solely responsible for evaluating, selecting and implementing it, and states that its availability through RapidCents implies no business relationship with the provider. Those are outside this page. Nor is every third party that touches a payment a subprocessor — the Acquirer and the Card Networks act for their own purposes under their own rules, as section 2 explains.
2. What this page covers, and what it does not
This page covers the categories of subprocessor RapidCents engages to provide the platform described in the Security Statement — the gateway, hosted checkout, payment links, Rapid.js, the dashboard, the virtual terminal, invoicing and recurring billing, point-of-sale software, the terminals RapidCents supplies and the APIs and SDKs that reach them — and the providers behind the public RapidCents websites. Four things it does not cover.
- The Acquirer and the Card Networks. Clause A.2 of the Services Agreement names the Acquirer as Elavon, LLC and Elavon Canada Company, the financial institution and Association member contracted by RapidCents to submit sales drafts and transaction information to the Associations and receive settlement funding from them. They are independent parties in the payment path, not processors acting on RapidCents’ instructions: section 6 of the Privacy Policy records that their handling is governed by their own rules, including the Visa and Mastercard operating regulations, and clause F.5 makes them third-party beneficiaries of the provisions that concern them.
- Third-party services a merchant chooses to connect, which clause B.6 addresses and section 1 above describes.
- Professional advisers. Auditors, lawyers and insurers receive information under a duty of confidence rather than as processors, as section 6 of the Privacy Policy sets out.
- Disclosures compelled by law, which are an obligation rather than a processing engagement and which no contract can override. Clause H.3 records that RapidCents’ obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and the Retail Payment Activities Act may require a report to a regulator or law enforcement without notice, and sometimes without RapidCents being permitted to say it has made one.
3. The categories of subprocessor RapidCents engages
Here are the kinds of company we engage and what each one can see. Which particular companies they are is what the register in section 9 is for.
The categories set out in the table below correspond to the service-provider categories disclosed in section 6 of the Privacy Policy. A category states what a provider is engaged to do and what personal information it can reach in doing it, which is the part that determines the risk. The identity of the individual providers is held in the register described in section 9.
One of the categories in the table cannot be declined while an account is open. Identity verification and sanctions screening exist because RapidCents is registered with the Financial Transactions and Reports Analysis Centre of Canada as a money services business and with the Bank of Canada as a payment service provider, and so carries obligations of its own for customer identification, beneficial ownership, record keeping, transaction monitoring, sanctions screening and reporting, as clause H.3 states. Submitting a Transaction to the Acquirer and the Card Networks cannot be declined either, because a transaction not submitted is not authorized — but that submission is the payment path described in section 2 rather than an engagement RapidCents has given to a subprocessor, and the register in section 9 names no provider in the card network and acquiring connectivity category.
Analytics is different: nothing in that category runs on the public websites unless the visitor has consented, and a Global Privacy Control signal is treated as a withdrawal of that consent, as the Cookie Policy describes. And where RapidCents performs a function itself, no category appears — section 7 of the Security Statement records that its systems and applications are developed in-house, which is why software development is not a category in the table.
| Category | Engaged to do | Personal information it can reach |
|---|---|---|
| Infrastructure and hosting | Operate the compute, storage, database and network the platform runs on, hold the daily backups, and deliver the public RapidCents websites and the assets a visitor’s browser loads with them. | Any category held on the platform. Card numbers are held as tokens, and the sensitive fields listed in section 3 of the Security Statement are encrypted at rest. A provider that only serves an asset to a visitor’s browser reaches the technical information that request carries and nothing held on the platform. |
| Card network and acquiring connectivity | Carry the authorization, clearing, settlement and dispute messages a Transaction generates to the Acquirer, which under clause A.2 submits them onward to the Associations. The register in section 9 names no provider in this category: RapidCents submits Transactions through its Acquirer, and this page does not assert an intermediary it cannot evidence. | Transaction information, and the card credential needed to authorize and settle it. |
| Identity verification and sanctions screening | Verify a business and its beneficial owners at onboarding, and screen against sanctions and watch lists. | Business and identity information, including government identification where verification requires it. |
| Fraud and risk scoring | Score a transaction or an account for risk, supply the device, velocity and behavioural signals the Risk Tools at clause H.8 use, and tell a person from an automated submission on the forms the public RapidCents websites publish. | Transaction information, technical information about the device, session and channel, and, on a public form, the technical information a browser sends when the check runs. |
| Communications delivery | Deliver the email, SMS and in-product messages RapidCents sends, including service, security and billing notices. | Contact information, marketing preferences, and the content of the message sent. |
| Support tooling | Run the ticketing, telephony, chat and knowledge systems through which RapidCents support answers you. | Contact and account information, and the content of support communications, including recordings where you are told a call is recorded. |
| Analytics | Measure how the public RapidCents websites are used, and only where the visitor has consented to the analytics category. | Technical information from your use of those websites, as the Cookie Policy describes. |
The Acquirer and the Card Networks appear in the second row because they are the destination of the messages that category carries. They are not themselves subprocessors, for the reason given in section 2, and they are named under their own role in the second table in section 9.
4. What RapidCents does before a subprocessor is engaged
Before a company goes near your data we assess it, put it under a written contract binding it to what we are bound to, limit it to the one job it was engaged for, and require it to keep confidential what it sees. These are conditions of engagement, not remedies applied after a problem.
Five commitments apply to every subprocessor, before it is engaged.
- Due diligence. RapidCents assesses a prospective subprocessor before entrusting personal information to it: the security controls it operates, where and under what legal framework it would process, and whether the work can be done with less personal information than it has asked for. Where it would process outside Canada, the assessment includes the privacy impact assessment described in section 7.
- A written contract imposing equivalent obligations. A subprocessor is engaged under a written contract binding it to protect the information to a standard comparable to the one RapidCents applies, to assist RapidCents in meeting its obligations under clause D.1, to notify RapidCents of a security incident affecting that information, and to return or delete what it holds when the engagement ends. Section 6 of the Privacy Policy states the same commitment.
- Purpose limitation. A subprocessor may use the information only for the service it provides to RapidCents — not for purposes of its own, not to build a profile or product of its own, and not for onward disclosure except as the contract permits. Section 5 of the Privacy Policy records that RapidCents does not sell personal information, does not use cardholder transaction detail to build advertising profiles, and does not disclose one merchant’s data to another. A subprocessor is not a route around any of those.
- Confidentiality. Personnel authorized to process the information are bound by confidentiality obligations: clause D.1, item 1.3(e), requires that of RapidCents, and RapidCents requires it in turn of a subprocessor. The definition of Confidential Information at clause E.2, and its four exceptions, apply to what is disclosed under the Agreement.
- Least data, not all data. A subprocessor receives the categories its function requires rather than the whole record. The table in section 3 states, for each category, what a provider in it can reach.
RapidCents is validated as a PCI DSS Level 1 service provider, and requirement 12.8 of the Payment Card Industry Data Security Standard applies to it directly: maintain a list of the third parties with which cardholder data is shared, carry out due diligence before engaging one, hold a written agreement in which the third party acknowledges its responsibility for that data, monitor each one’s compliance status, and record which requirements each party manages. RapidCents is assessed against those requirements.
5. Engaging a subprocessor does not move RapidCents’ obligations
You never have to chase a supplier of ours. Bring the request, the complaint or the incident to us; dealing with the provider is our job.
Engaging a subprocessor does not divide RapidCents’ obligations between RapidCents and the provider. The commitments at clause D.1, items 1.3(a) to 1.3(f), of the Services Agreement — processing only on the merchant’s documented instructions, appropriate technical and organizational security measures, assistance with data subject requests, notice without undue delay of a data breach affecting Customer Data, personnel bound to confidentiality, and return or deletion at the end of the engagement — continue to be owed to the merchant by RapidCents, whichever company performs the underlying work.
So a merchant does not have to pursue a subprocessor. A request, a complaint or an incident is raised with RapidCents, and RapidCents deals with the provider: section 12 of the Privacy Policy gives the route for a privacy request, clause A.6 the escalation path for an unresolved complaint, and section 10 of the Security Statement the handling of an incident affecting a merchant’s data or account.
The limitation of liability at clause E.5 continues to apply to those obligations and is neither enlarged nor narrowed by this page. The Data Processing Addendum governs the point contractually, and clause 19 of that addendum records that it applies to every merchant and binds RapidCents without a separate signature.
6. Processing outside Canada
Some of the work happens outside Canada, including in the United States. While data is there it is subject to that country’s laws, including access by its courts and authorities. No contract can change that, and we would rather say so than let you discover it.
RapidCents operates in Canada and in the United States, and some of the subprocessors it engages store or process personal information outside the province or the country in which the individual concerned lives, including in the United States. Section 9 of the Privacy Policy records the same fact.
The consequence is worth stating plainly. While personal information is in another jurisdiction it is subject to that jurisdiction’s laws, and may be accessible to its courts, law enforcement agencies and national security authorities through the legal processes available there. A contract between RapidCents and a subprocessor cannot displace the law of the place where the processing happens, and this page does not suggest otherwise. What a contract can do is bind the provider to a standard of protection, to purpose limitation, to confidentiality and to notification — the commitments in section 4, which is why the assessment in section 7 is made before a provider in another jurisdiction is engaged rather than after. Where you need to know the country a category of your data is processed in, the register in section 9 states it for each provider it records one for, and gives the route for asking where it does not.
7. Cross-border transfer under Canadian law
Canadian law does not forbid sending data abroad. It makes us stay accountable for it, put the protection in the contract, and be open that it happens. Quebec adds an assessment beforehand, a written agreement, and a duty to tell people at collection.
This section and the next describe different regimes. Which one applies to a given piece of personal information turns on where the individual is, not on where the merchant is incorporated. Nothing here asserts that Canadian law governs a United States merchant’s data; section 8 is the position there.
In Canada, the Personal Information Protection and Electronic Documents Act does not prohibit transferring personal information to a service provider in another country. It treats the transfer as a use for processing and holds the transferring organization accountable for the information while it is in the provider’s hands, requiring contractual or other means to provide a comparable level of protection. It also carries an openness obligation, which is why section 6 exists: an organization is expected to be transparent that personal information may be processed in another jurisdiction and may be accessible to that jurisdiction’s courts, law enforcement and national security authorities.
For an individual in Quebec, the Act respecting the protection of personal information in the private sector, as amended by Law 25, goes further. Before personal information is communicated outside Quebec, an assessment of the privacy-related factors must be carried out, taking into account the sensitivity of the information, the purposes of its use, the protection measures — including contractual measures — that would apply to it, and the legal framework of the jurisdiction where it would be processed. It may be communicated only if that assessment establishes that it would receive adequate protection, and the communication must be the subject of a written agreement that takes the results of the assessment into account. Law 25 also carries a separate transparency obligation that the assessment does not satisfy: a person collecting personal information must inform the individual, at the time of collection, of the possibility that it could be communicated outside Quebec. That is why this page states that some processing occurs outside Canada rather than describing the safeguards alone.
Alberta’s Personal Information Protection Act adds a requirement of its own: an organization using a service provider outside Canada must set out in its policies the countries outside Canada in which the collection, use or disclosure takes place and the purposes for which that provider has been authorized to act, and must tell individuals how to obtain that information and whom to ask about it. That is why the register in section 9 carries a processing country for each provider, states it where the register records one, leaves it visibly blank where it does not rather than supplying a country by inference, and sets out both whom to ask and how to obtain the current full list — which is the half of that requirement a register on its own does not satisfy. British Columbia’s Act applies to activity in that province and, like Alberta’s, holds an organization responsible for personal information it has placed in a service provider’s custody.
8. Cross-border transfer under United States law
US state privacy laws do not restrict sending data across a border. They regulate what must be in the contract with a provider and what a privacy notice must disclose. Engaging a provider on those terms is not a sale of your data.
In the United States there is no comprehensive federal privacy statute of general application, and the state comprehensive privacy laws now in force do not restrict the transfer of personal data outside the country as such. What they regulate is the contract and the notice.
A controller that engages a processor or service provider must have a written contract setting out the nature and purpose of the processing, the type of personal data, the duration, and the rights and obligations of each party; binding the processor to a duty of confidentiality; requiring it to delete or return the data at the end of the engagement; requiring it to assist with security and with consumer rights requests; and requiring any subcontractor it engages to be bound by a written contract imposing the same obligations. The commitments in section 4 are written to meet that standard. Those laws also require a business to disclose in its privacy notice the categories of third parties to which personal information is disclosed: this page and section 6 of the Privacy Policy are that disclosure at the category level, and the register in section 9 supplies the identities it records, together with the route to the current full list.
For a resident of a United States jurisdiction with a comprehensive privacy statute, RapidCents does not sell personal information as that term is defined in those laws, and engaging a subprocessor is not a sale: a provider bound by the purpose limitation in section 4 receives the information to perform a service for RapidCents and for no purpose of its own. Section 2 of the Privacy Policy states the same, and section 8 of that policy sets out how such a resident exercises the rights those laws grant, including the right to appeal a decision on a request.
If you are a United States merchant, the obligations in section 7 are not being asserted against you. They are stated because RapidCents is a Canadian company processing personal information about individuals in Canada, and because a merchant with Canadian customers inherits a version of them through its own privacy notice.
9. The register, and how to obtain the current full list
The companies we engage are named below, with what each is engaged to do and, where the register states one, the country it processes in. The parties in the payment path who are not our suppliers are named too, in a second table, because you are asking who touches your data rather than how we classify them. The register is complete as to the companies in it, it is not the whole supply chain, and the current full list is yours for the asking.
RapidCents maintains a register of the subprocessors it engages. For each one it states the name of the provider, the category in section 3 it falls in, what it is engaged to do, and, where the register states one, the country in which it processes — the information a privacy notice, a vendor questionnaire and an Alberta policy disclosure each need, kept in one place so the three cannot diverge. It is published below, and a processing country the register does not state is left visibly blank rather than supplied by inference; the routes set out below are how to ask for it.
The register is complete as to the parties named in it, and nothing has been added to make it read as fuller than it is. It is not the whole supply chain. RapidCents engages providers in the infrastructure and hosting, identity verification and sanctions screening, communications delivery, support tooling and analytics categories described in section 3 that the register below does not name, and the Approved Scanning Vendors and third-party penetration testers described in section 8 of the Security Statement are not named there either. The current full list is provided on request, by the routes set out below. A short register is not evidence of a short supply chain, and this page says so rather than letting the table imply otherwise.
What RapidCents undertakes about keeping the register current is this, and deliberately no more than this. The register carries the date it was last reviewed, published beneath it. RapidCents reviews it whenever a provider in it is added, replaced or removed and, in any event, at least once in every twelve months, and republishes this page where a review changes it. Where a change materially affects how personal information is handled, section 10 applies and notice is given before it takes effect. RapidCents does not undertake that this page reflects a change on the day the change is made. It undertakes that the date of the last review is published beside the register, so that how current the register is can be read rather than assumed.
To obtain the current full list, ask through /contact, by email to [email protected], or by writing to the Privacy Officer at the address in section 12 of the Privacy Policy. The same routes are how to ask for the country a provider processes in where the register leaves that cell blank. It is supplied in whatever form the review needs — within a completed vendor security questionnaire, as an appendix to a Data Processing Addendum, or on its own. The Attestation of Compliance for the PCI DSS Level 1 validation is not published; section 8 of the PCI Compliance page sets out how to request that. What is published, and can be read without asking anyone, is the rest of the material a security or procurement review works through: the Security Statement, the Data Processing Addendum, the Privacy Policy, the Accessibility Statement and the vulnerability disclosure route, which the Trust Centre at /company/trust gathers in one place.
The second table names the parties in the payment path that are not subprocessors. They are set out separately from the register, and not inside it, because listing a Card Network as a subprocessor would represent that RapidCents contracts for its handling of personal information and can bring that handling to an end; section 2 explains why neither is so. They are named all the same. A merchant asking who touches its data is asking about the payment path rather than about a classification, and a page that answered only the classification would have withheld the answer.
This page states the categories, the commitments and the law that governs them; the register states who. Holding the names in one maintained register rather than restating them across several documents is what keeps the two from falling out of step.
| Provider | Category in section 3 | Engaged to do | Processing country |
|---|---|---|---|
| The content delivery network that serves the site | Infrastructure and hosting | Serve the public RapidCents website from an edge network. Every request a visitor makes reaches it before it reaches RapidCents, so it necessarily receives the network address the request comes from, the page requested and the identification the browser sends. RapidCents also reads the country the network reports, in order to serve the Canadian or the United States site. | — |
| Cloudflare, Inc. (Turnstile) | Fraud and risk scoring | Run the bot-mitigation check the statement comparison form at /pricing/fee-check presents before a statement is accepted. The check runs in the visitor’s browser, which contacts the provider directly and discloses to it the network address, the browser identification and the interaction signals the check uses to tell a person from an automated submission. | — |
| Google LLC (reCAPTCHA) | Fraud and risk scoring | Run the same bot-mitigation check, on the same form, where RapidCents’ configuration selects this provider rather than the other. It reaches the same information, for the same purpose. | — |
| Google LLC (Google Fonts) | Infrastructure and hosting | Serve the typefaces the public RapidCents websites are set in. Where a page requests them from the provider rather than from RapidCents’ own servers, the stylesheet and the font files are requested by the visitor’s browser directly, which discloses to the provider the browser’s network address and the identification it sends with a request. It reaches nothing held on the platform. | — |
Named by role rather than by company. RapidCents is finalising which content delivery network is named here and will publish the company name in this register before it is relied upon. The role, the data the network necessarily receives and the purpose above are complete and accurate as stated. The form loads one bot-mitigation provider at a time, and which one it loads is set in RapidCents’ configuration rather than in the page a visitor receives. Both providers the site implements are named here, because a register that named only one would depend on a setting the reader cannot check. A processing country shown as — is one this register does not state for that provider. It is left blank rather than filled in by inference: a country stated wrongly is worse than a country left to be asked for, because Alberta’s Personal Information Protection Act makes the disclosure of the country a requirement rather than a courtesy. Ask by the routes this section sets out for the country a particular provider processes in. Register last reviewed 26 August 2026.
| Party | Role in the payment path | What it does, and under whose rules |
|---|---|---|
| Elavon, LLC and Elavon Canada Company (together, the Acquirer) | Acquirer | The financial institution and Association member RapidCents has contracted with. Clause A.2 of the Services Agreement records that it submits sales drafts and transaction information to the Associations on RapidCents’ behalf, receives settlement funding for those transactions from the Associations, and disburses those funds to RapidCents for onward settlement to the merchant. It acts under its own Association membership rather than on RapidCents’ instructions. |
| Visa | Card network | Operates the network a Transaction on its cards is authorized, cleared, settled and disputed through, under operating regulations it writes and RapidCents cannot vary. |
| Mastercard | Card network | Operates the network a Transaction on its cards is authorized, cleared, settled and disputed through, under operating regulations it writes and RapidCents cannot vary. |
| American Express | Card network | Operates the network a Transaction on its cards is authorized, cleared, settled and disputed through, under operating regulations it writes and RapidCents cannot vary. |
| Discover | Card network | Operates the network a Transaction on its cards is authorized, cleared, settled and disputed through, under operating regulations it writes and RapidCents cannot vary. |
| Diners Club | Card network | Operates the network a Transaction on its cards is authorized, cleared, settled and disputed through, under operating regulations it writes and RapidCents cannot vary. |
| Interac | Card network | Operates the network a Transaction on its cards is authorized, cleared, settled and disputed through, under operating rules it writes and RapidCents cannot vary. Section 1 of the KYC Policy names it among the networks whose operating regulations bind an acquirer and its processor. |
| The bank that issued the card | Issuer | Receives the authorization request for a Transaction on the card it issued and decides it, and is the party a cardholder raises a dispute with. Clause 11 of the Data Processing Addendum records that issuing banks receive Transaction Data as participants in the payment system and handle it under their own rules. |
An issuing bank is named by the card a Customer chooses to pay with rather than by RapidCents, so this row is a class of party rather than a company. RapidCents neither selects it nor instructs it. This table has no processing-country column. RapidCents neither engages these parties nor decides where they process, so the answer is theirs to give rather than RapidCents’ to state, and a column of dashes would suggest an answer was being withheld. Their handling is governed by their own rules, including the Visa and Mastercard operating regulations, as section 6 of the Privacy Policy records.
10. Notice of a change, and what to do if you object
If the supply chain changes in a way that materially affects how personal information is handled, you get thirty days’ notice first. If you are not comfortable with a change, tell us and we will explain it. If that does not settle it, you can close your account — there is no cancellation fee and no early termination fee.
A supply chain changes: a provider is replaced, a category gains one, a provider moves the region it processes in. Where a change materially affects how personal information is handled, section 14 of the Privacy Policy applies and notice is given at least thirty (30) days before it takes effect. Notice reaches you by the routes in clause F.3 of the Services Agreement — the dashboard, the email address on your account, or the address in your account information — and is effective when sent or posted. In the United States, the Electronic Signatures in Global and National Commerce Act and the Uniform Electronic Transactions Act as enacted in your state — or, in New York, that state’s own legislation — give it the same legal effect as a notice on paper, as the Electronic Communications Consent explains.
If you object to a change, say so. Write to the Privacy Officer at the address in section 12 of the Privacy Policy, or email [email protected], setting out which provider or category concerns you and why. RapidCents will tell you what the provider is engaged to do, what it can reach, where it processes and what its contract requires of it. Those four answers come from the register in section 9, the category table in section 3 and the commitments in section 4, which is what lets an objection be answered from a document rather than from an assurance. Where an objection is not resolved, the complaint procedure at clause A.6 applies: Support first, the Executive Office if the matter is not resolved or closed within fourteen (14) business days, and the final escalation route after a further five (5) business days without a substantive response.
Two limits are worth being straight about. RapidCents cannot remove a subprocessor engaged to meet an obligation it has no option of declining, as section 3 explains. And an objection is not a veto: no separate objection window has been set, as the last paragraph of this section and clause 11 of the Data Processing Addendum both record, and the remedy the Services Agreement gives a merchant who will not accept a change is the one in the next paragraph — closing the account, with no early termination fee and no cancellation penalty of any kind.
Where a change is one you are not prepared to accept, you may close your account. Clause A.4 of the Services Agreement states that RapidCents charges no early termination fee and imposes no cancellation penalty of any kind, and that a merchant is free to close its account at any time and for any reason. Where a change amounts to a material adverse change to the terms of the Agreement unilaterally imposed by RapidCents, the cancellation right at clause A.3 applies on its own terms, by written notice within ninety (90) days of the notice of the change and on return of the account closure form that clause requires. Clause A.5 preserves your liability for transactions already processed, including chargebacks and refunds arriving after closure.
RapidCents has not set a separate objection window for a subprocessor change, and this page does not state one it does not have. Raise an objection as soon as you are able and, wherever possible, before the change takes effect; the thirty (30) day notice period above is the period in which to do it.
11. How this page relates to the other documents
This page is a description of practice. It is not the contract and creates no rights of its own. Where anything on it differs from the Services Agreement, the Agreement governs; clause F.6 records that the Agreement, with the policies and documents incorporated into it by reference, is the entire agreement between the parties on its subject matter.
The Data Processing Addendum is where the subprocessor terms are contractual. Section 3 of the Privacy Policy states that where RapidCents acts as a processor, the Addendum sets out the commitments governing that role, and clause 19 of the Addendum records that it applies to every merchant and binds RapidCents without a separate signature; a merchant whose own procurement process requires a signed counterpart asks for one at [email protected]. Its terms govern the authorization of subprocessors, the notice given of a change and the merchant’s rights on objection, and take precedence over this page.
The Privacy Policy governs RapidCents’ processing of personal information for its own purposes — about merchants, merchant staff, applicants, website visitors and people who contact RapidCents, and the narrower set of activities section 3 of that policy places on the controller side even though they reach a merchant’s own Customers — for which RapidCents is the controller. This page sits underneath both roles, because a single subprocessor may handle personal information in either.
The Security Statement describes the controls operating in the RapidCents environment and the PCI Compliance page describes what the Level 1 validation covers and where it stops. Neither says anything about a subprocessor’s own environment; section 4 governs that. And as the Security Statement says of itself, this page describes practices: it is not a service level, a warranty, or a representation that any system is free of vulnerabilities, and the disclaimer at clause E.4 applies to it on the same footing.
12. What remains your responsibility
You still have to tell your own customers that their data goes to us and to the companies we engage, and you still have to hold the consents for it. We cannot obtain them on your behalf.
RapidCents publishing this page does not discharge a merchant’s obligations to its own customers. A merchant who treats it as though it did will be the party a regulator asks.
- Hold the consents. Clause D.1, item 1.2(a), requires you to have all necessary rights, permissions and consents to collect, process, use and share Customer Data with RapidCents and its service providers. The consent is yours to obtain.
- Give the notice. Item 1.2(b) requires clear and accurate privacy notices to your customers disclosing how their data will be used, including the sharing of that data with RapidCents for payment processing purposes. Where your customers are in Quebec, that notice must also inform them at collection of the possibility that the information could be communicated outside Quebec.
- Disclose the categories where the law requires it of you. A United States state privacy law obliging you to disclose the categories of third parties to which you disclose personal information places that obligation on you, not on RapidCents. Section 3 gives you the categories; section 9 names the providers the register records and gives the route to the current full list, if your notice needs them.
- Answer your own customers. Item 1.2(f) makes you responsible for responding to access, deletion and other rights requests from your customers. RapidCents will assist to the extent reasonably possible, as item 1.3(c) requires, but the request is answered by you.
- Tell RapidCents when something goes wrong. Item 1.2(e) requires prompt notice of any actual or suspected data breach affecting Customer Data, and clause D.2, item 2.3, requires immediate notice of a suspected, alleged or confirmed compromised data event by email to both [email protected] and [email protected] — including one occurring at one of your own third-party service providers.
- Keep your own list. Clause B.6 makes you solely responsible for evaluating, selecting and implementing any third-party service you connect, and requirement 12.8 of PCI DSS applies to you in respect of your own service providers exactly as it applies to RapidCents in respect of its.
Questions about this document
Write to RapidCents Inc., 515 Consumers Road, Unit 210, North York, Ontario, M2J 4Z2, or call +1-844-957-2743. In the United States: 43300 Southern Walk Plaza, #166, Ashburn, Virginia 20148, or call +1-202-902-6226.





