This Privacy Notice describes how daVinci Payments, Inc. (“we”, “our”, “us” or “daVinci”) manages the personal data we collect about users of our Web sites and mobile applications, as well as the personal data we collect in providing our products and services or when individuals communicate with us about our Web sites, mobile apps, products or services. It explains (1) what personal data we collect, (2) how we use the personal data we collect, (3) how long we hold the data, (4) what and with whom we share it with, (5) how to control your privacy options with daVinci, (6) what are your rights, and (7) certain other privacy information. In addition to these items, we also process personal data on behalf of our clients and card or payment issuers. When we do so, we process personal data solely to provide services to our clients and card or payment issuers, we collect, use and disclose the data only under the instructions of our client or the card or payment issuer, and our processing of the data is subject to their instructions and privacy notices.
WHAT DATA WE COLLECT ABOUT YOU
daVinci may collect personal data, for example through our websites or when you contact customer service, which may include the following, as applicable (“Personal Data”):
- Full name, personal or business contact information including physical mailing address, email address and telephone number.
- Contact preferences and other business information that helps us do business with you.
- Technical information such as login information, IP address, device and operating system.
- Other data with your consent or as allowed or required by applicable law.
HOW WE USE YOUR DATA
We collect Personal Data about you to operate and to support our services and products only. We may use this Personal Data to:
- Send administrative material to you, such as changes to our terms, conditions, and policies.
- Provide access to our website and customer service.
- Provide technical support.
- Send you alerts that you requested.
- Identify areas where our products and services can be enhanced.
- Monitor for fraud and mitigate risk.
We may also use your Personal Data in other instances with your consent or as allowed or required by law.
HOW LONG WE HOLD YOUR DATA
We may hold Personal Data as long as needed or relevant for the practices described in this Privacy Notice or as otherwise applicable by law. Actual hold periods differ depending on the type of services and products. The principles we use to determine the holding periods include the following:
- Personal Data needed to provide our services and products as described in this Privacy Notice;
- Personal Data needed for auditing purposes;
- Personal Data needed to troubleshoot problems or to assist with investigations;
- Personal Data needed to enforce our policies; and
- Personal Data needed to comply with legal requirements.
Regulations require financial institutions to obtain, verify, and record information that identifies each person for whom we open or have established an account. With respect to such records, daVinci generally holds those records for a minimum of seven years.
WHAT AND WITH WHOM WE SHARE
We may share your Personal Data:
- With organizations and partners that help us operate our business by providing services such as website hosting, data analysis, information technology, customer service, email delivery, auditing and other similar services.
- With partners and other vendors that perform services on our behalf, such as network services support, including data processing services, customer service, call center services, information technology services, internal audit, management, or administrative purposes.
- To comply with the law or other legal responsibilities such as responding to subpoenas, including laws and other legal duties outside your country of residence.
- To answer requests from government authorities including authorities outside your country of residence.
- To protect our rights, business operations and possessions, or that of our users, employees and partners.
- To investigate, stop, or take action concerning possible or suspected illegal activities, fraud, or violations of our terms and conditions.
HOW TO CONTROL YOUR PRIVACY OPTIONS
You can update your account profile online or by email. We maintain electronic records of your Personal Data for the purposes described in this Privacy Notice. You will be able to access and edit your Personal Data on the website listed on the back of the card. Otherwise, you may contact us at the e-mail address listed at the bottom of this Notice. Your right to access, correct or delete your Personal Data indicated in our records is subject to applicable law including our right to retain documentation of our compliance with applicable legal requirements and technology limitations. We may take reasonable steps to confirm your identity before giving access or making modifications to your Personal Data.
If we receive data from other sources, we may direct you to contact those sources. Please note that we are not responsible for permitting you to review, or for updating or deleting personal data that you provide to those sources or any other third-party.
When you provide us with your Personal Data it is only used for the purposes of providing products and services as described in this Privacy Notice. You have the option to opt-out of certain uses and disclosures of your Personal Data as outlined in this Notice. If you would like to opt-out of these uses or disclosures of your Personal Data you may contact us at the email address listed at the bottom of this Notice.
WE USE BROWSER INFORMATION
- Identify new or past users;
- Save your password if you are registered on our website;
- Enhance our website and troubleshoot issues.
- Investigate, stop, or take action concerning possible or suspected illegal activities, fraud, or violations of our terms and conditions.
You can adjust cookies and tracking tools on our Website. Your web browser may give you the ability to adjust cookies. How you do so depends on the type of cookie. Certain web browsers can be set to clear past and reject future cookies. If you block cookies on your browser, certain features of our website may not work. Additionally, if you limit or delete cookies, not all of the tracking activities we have defined here will stop. The choices you make are both browser and device specific. For more information on cookies and how to manage them, visit www.allaboutcookies.org.
WHAT ARE YOUR RIGHTS UNDER EU & uk PRIVACY LAW
We adhere to applicable data protection laws in the European Union ("EU") and the United Kingdom (“UK”), when relevant and appropriate, including the General Data Protection Regulation (“GDPR”). If you are located in the EU or the UK, you have the right to:
- Request access, rectify or delete your Personal Data;
- Object, port or restrict the processing of your Personal Data;
- Withdraw any consent you have provided to our processing of your Personal Data;
You may exercise these rights free of charge. However, we may charge a reasonable fee or refuse to act on a request if it is manifestly unfounded or excessive, in particular because of its repetitive character. In some situations, we may refuse to act or may impose limitations on your rights if, for instance, your request is likely to adversely affect the rights and freedoms of others, prejudice the execution or enforcement of the law, interfere with pending or future litigation, or infringe applicable law. You have the right under applicable EU and UK privacy law to file a complaint with the relevant Data Protection Authority.
If you wish to exercise any of theses rights, please contact us using the email address listed at the bottom of this Notice.
OTHER PRIVACY INFORMATION
We process your Personal Data, on specific legal grounds. We do so with your consent, to fulfill the contractual requirements we have with you, comply with our legal responsibilities, or as needed to deliver our services and products and for other legitimate business interests for the purposes described in this Privacy Notice.
We protect your Personal Data. We implement security policies, processes and technical security solutions to protect Personal Data which includes various network safeguards, logging and alerting. In order to perform certain obligations, our authorized employees and service providers will need access to your Personal Data. We contractually require our service providers to protect your Personal Data.
Data storage and transfers. We store Personal Data in the United States. If you reside outside of the U.S, you understand that we transfer Personal Data to the United States. Our products and services and associated practices comply with privacy provisions as set forth by the US government as well as the Privacy Shield Framework as set forth by the US Department of Commerce and GDPR as set forth by the EU and the UK. When we transfer your Personal Data to service providers or third parties as outlined in this Privacy Notice, we rely on contractual clauses to administer the transfer of that Personal Data and uphold those entities to protecting the data as described in this Privacy Notice or as required by law.
Our Services are not intended for children. Our Services are meant for adults and are not for children. We do not intentionally collect Personal Data from children under 13 without authorization from a parent or legal guardian. If you think your child under 13 has sent us data, you can contact us at compliance@daVinciPayments.com.
Our Services may link to third-party services that we do not manage. If you click a link to a third-party website, you will be taken to sites that we do not control. This Privacy Notice does not apply to the privacy practices of those websites. Please read the privacy notice of those websites. We are not liable for these third-party practices.
This Privacy Notice may be updated at any time. We may change our Privacy Notice from time to time. We may inform you of any changes to our Privacy Notice as required by law. Please check the Website periodically for updates. This Privacy Notice was last modified on 06/2019.
To contact us, if you have additional questions, concerns or wish to file a complaint regarding your Personal Data, you may e-mail our Data Protection Officer at compliance@daVinciPayments.com. We are committed to resolving any questions you may have.