This Privacy Notice (the “ Notice”) is provided by Mastercard International Incorporated and its affiliates, including but not limited to Ekata, Inc. (“Mastercard,” “we,” or “us”). Mastercard respects your privacy.
This Privacy Notice applies to the processing of Personal Information collected in the context of our website https://ekata.com/, through the services that we offer to our business customers (the “Customers”), and any features or online services provided by Mastercard and its affiliate, Ekata,Inc. that post or include a link to this Privacy Notice (collectively, the “Services”).
This Privacy Notice describes the types of Personal Information we collect in connection with the Services, the purposes for which we process that Personal Information, the parties with whom we may share it and the measures we take to protect its security. It also tells you about your rights and choices with respect to your Personal Information, and how you can contact us about our privacy practices.
Specific privacy notices may apply to some of our products and services. For more information about Mastercard’s privacy practices in other contexts, please visit Mastercard’s Global Privacy Notice at https://www.mastercard.com/us/en/global-privacy-notice.html.
For French version, please visit https://ekata.com/privacy-policy-fr/
For Spanish version, please visit https://ekata.com/privacy-policy-es/
For German version, please visit https://ekata.com/privacy-policy-de/
For Chinese version, please visit https://ekata.com/privacy-policy-zhcn/
“ Personal Information” means any information relating to an identified or identifiable individual. We may collect the following types of Personal Information:
For the purpose of this Privacy Notice, unless otherwise specified, “ Personal Information” means any information relating to an identified or identifiable individual. In connection with the provision of the Services, we obtain Personal Information relating to you in the situations described below.
Personal Information Provided by You
Personal Information Provided by Customers
Personal Information Derived from Customer Data
Third parties
Personal Information Automatically Obtained from Your Interaction with the Services
We May Use Your Personal Information to:
We set out below the purposes for which we process Personal Information. We indicate the categories of Personal Information per processing purpose. We will only process your Personal Information when we have a valid legal ground for the processing in accordance with applicable law, depending on the country in which you are located. However, please note that even though the chart below may not list consent as a legal basis for each processing activity, in some countries consent is the only or most appropriate legal basis for the processing of Personal Information, and in those countries we rely on consent for all processing activities. In certain cases, this consent may be obtained on our behalf from our Customers.
|
|
|
|
|
Provide Services to our customers for fraud and incident prevention and servicing customer accounts, including activities such as facilitate payments for the Services, communicate with our customers, connect third party services for customers, personalize the services at customers’ requests, and audit interactions with customers. |
We, and our Customers, have a legitimate interest in combatting fraud or fraudulent use of our Customers’ services. We may also rely on the “performance of a contract” legal ground when we process Personal Information to fulfill individuals’ requests e.g., to respond to individuals’ inquiries. |
Account Information |
|
Maintain the Services in good working order, and to manage cyber threats, risk exposure, and franchise quality with respect to the integrity and security of our Services and internal systems. |
We have a legitimate interest in ensuring the safety, security and performance of our Services. |
Account Information |
|
Operate, evaluate, and improve our business (including developing new products and services). |
We have a legitimate interest in improving and developing our business, products, and services. |
Account Information |
|
Provide tailored business communication and marketing. |
We have a legitimate interest in promoting our business. When we send electronic direct marketing communications, or when we tailor our advertising, we will obtain individuals’ prior consent if required in accordance with applicable laws. |
General Communication Information |
|
As may be required by applicable laws and regulations, including for compliance with Know Your Customers, Anti-Money Laundering, anti-corruption and sanctions screening requirements, or as requested by any judicial process, law enforcement, or governmental agency having or claiming jurisdiction over Mastercard or Mastercard’s affiliates. |
Compliance with legal obligations |
General Communication Information |
|
Protect against and prevent fraud and cyber threats, unauthorized transactions, claims and other liabilities, and manage risk exposure and franchise quality with respect to the integrity and security of our Services. |
We, or a third party, have a legitimate interest in protecting against legal claims. |
General Communication Information |
|
Perform due diligence reviews, accounting, auditing, billing, reconciliation and collection activities. |
We have a legitimate interest in managing our Customer, vendor and partner relationships as necessary to operate our business. |
Account Information |
|
Protect our Customer and others against fraud, cyber incidents and strengthen the cyber resilience of our Customer’s operations. |
We, or our Customers, have a legitimate interest in combatting fraud or fraudulent use of our Customers’ services. |
Account Information |
We May Share Personal Information with:
Mastercard may provide your Personal Information to the following third parties for the purposes set out below:
Subject to applicable law, you have the right to:
Subject to applicable law, you have the right to:
Those rights may be limited in some circumstances by local law requirements. United States residents may refer to Section 11 below for additional information.
If you are a resident of the European Union and would like to submit a request, please submit your request on Mastercard Identity’s “ My Data” portal or email us at ekataprivacyanddataprotection@mastercard.com.
If you are a resident of a U.S. State which offers the type of individual rights outlined here, please submit your request on submit your request on Mastercard Identity’s “ My Data” portal, email us at ekataprivacyanddataprotection@mastercard.com, or call our toll-free number at +1 (855) 927-1072.
We maintain appropriate security safeguards to protect your Personal Information and only retain it for a limited period of time.
We maintain appropriate administrative, technical and physical safeguards to protect Personal Information against accidental or unlawful destruction, accidental loss, unauthorized alteration, unauthorized disclosure or access, misuse, and any other unlawful form of processing of the Personal Information in our possession. The types of measures we take vary depending on the type of data, and how it is collected and stored. We restrict access to Personal Information about you to those employees who need to know that information to provide products or services to you.
We also take measures to delete your Personal Information or keep it in a form that does not permit your identification when this information is no longer necessary for the purposes for which we process it or when you request their deletion, unless we are required by law to keep the information for a longer period. In principle, we keep Customer Data for 90 days for troubleshooting purposes, and we keep Insights for 3 years to improve our fraud prevention and identity verification services.
We may transfer your Personal Information outside of your country, including to the United States, in compliance with the Mastercard Binding Corporate Rules and other data transfer mechanisms.
Mastercard is a global business. We may transfer or disclose Personal Information to recipients in countries other than your country, including the United States, where we are headquartered. These countries may not have the same data protection laws as the country in which you initially provided the information. When we transfer or disclose your Personal Information to other countries, we will protect that information as described in this Privacy Notice.
We comply with applicable legal requirements when transferring Personal Information to countries other than the country where you are located. In particular, we have established and implemented a set of Binding Corporate Rules (“ BCRs”) that have been recognized by EEA data protection authorities as providing an adequate level of protection to the Personal Information we process globally. A copy of our BCRs is available here. We may also transfer Personal Information to countries for which the EU Commission has issued an adequacy decision or use contractual protections for the transfer of Personal Information to third parties, such as the European Commission’s Standard Contractual Clauses. You may contact us as specified in the “How to Contact Us” section below to obtain a copy of the safeguards we use to transfer Personal Information outside of the EEA.
You may choose to use certain features for which we partner with other entities that operate independently from us.
You may choose to use certain features for which we partner with other entities or click on links to other websites for your convenience and information. These features may operate independently from us. They may have their own privacy notices or policies, which we strongly suggest you review. To the extent any features or linked websites you visit are not owned or operated by us, we are not responsible for the sites’ content, any use of the sites, or the privacy practices of the sites.
The Services are not directed to, or intended for, children under the age of eighteen years old. Mastercard does not knowingly collect information from children under the age of eighteen.
This Privacy Notice may be updated periodically to reflect changes in our privacy practices.
This Privacy Notice may be updated periodically to reflect changes in our Personal Information practices. We will notify you of any significant changes to our Privacy Notice and indicate at the top of the notice when it was most recently updated. If we update this Privacy Notice, in certain circumstances, we may seek your consent.
If you have any questions or comments about the processing of your Personal Information that a Customer provided to us in the context of our fraud prevention and identity verification services, or if you would like to exercise your rights and choices in this context, please contact the relevant Customer.
If you are located in the United States, Ekata, Inc. and Mastercard International Inc. would be the entities responsible for the processing of your Personal Information. You can email us at ekataprivacyanddataprotection@mastercard.com; or write to us at:
Mastercard Identity c/o Ekata.
1201 2nd Ave, Suite 3600,
Seattle, WA 98101,
United States
If you are located in the EEA, UK, or Switzerland, Mastercard Europe SA is the entity responsible for the processing of your Personal Information. You can e-mail us at: ekataprivacyanddataprotection@mastercard.com; or write to us at:
Europe Data Protection Officer
Mastercard Europe SA
Chaussée de Tervuren 198A
B-1410 Waterloo
Belgium
If you are located in the United States, Ekata, Inc. and Mastercard International Inc. would be the entities responsible for the processing of your Personal Information. You can email us at ekataprivacyanddataprotection@mastercard.com; or write to us at:
Mastercard Identity c/o Ekata.
1201 2nd Ave, Suite 3600,
Seattle, WA 98101,
United States
If you are located in Brazil, Mastercard Brasil Soluções de Pagamento Ltda. Is the entity responsible for the processing of your Personal Information. You can email us at ekataprivacyanddataprotection@mastercard.com; or write to us at:
Brazil Data Protection Officer
Mastercard Brasil Soluções de Pagamento Ltda.
Avenida das Nações Unidas, 14.171, 20º andar, Crystal Tower
São Paulo/SP
Brasil
CEP 04794-000
If you are located in Asia (excluding India), the Middle East, or Africa, Mastercard Asia/Pacific Pte. Ltd. Is the entity responsible for the Processing of your Personal Information. You can email us at ekataprivacyanddataprotection@mastercard.com; or write to us at:
Asia Pacific, Middle East and Africa Data Protection Officer
Mastercard Asia/Pacific Pte Ltd
3 Fraser Street, DUO Tower, Level 17
Singapore 189352
This U.S. Privacy Addendum supplements the information contained in this Privacy Notice and our Applicant Privacy Notice for U.S. residents, as indicated below.
Additional disclosures for U.S. residents, other than California Residents
If you are a U.S. resident from whom we collect Personal Data as a controller, you may have certain rights under an applicable U.S. state privacy law. You may rely on the disclosures in this Privacy Notice regarding how we collect, use, and disclose your personal information as well as the choices you can make related to your personal information.
Your Rights and Choices
In addition to the rights identified in Section 4 (“Your Rights and Choices”) above, you may have the right to opt out of the processing of the personal information for purposes of targeted advertising or profiling in furtherance of decisions that produce legal or similarly significant effects concerning you and the right to appeal a decision we make with respect to your privacy rights.
You (or, where permitted by law, your authorized agent) can exercise your rights by submitting a request as described in Section G (“Authorizing an Agent”) of the Additional Disclosures for California Residents below.
Please refer to Section G of the Additional Disclosures for California Residents above for more information on exercises these rights.
Additional Disclosures for California residents
If you are a California resident from whom we collect Personal Information as a business under the California Consumer Privacy Act of 2018 (as amended by the California Privacy Rights Act of 2020) (“CCPA”), you may rely on this Privacy Notice and the additional information below.
If you are a job applicant who is a California resident, please refer to our Applicant Privacy Notice here for further information .
For the purpose of this section for California residents, “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, or as otherwise defined by the CCPA. Personal Information does not include information that is publicly available, deidentified, or aggregated (as those terms are defined in the CCPA) or otherwise excluded from the scope of the CCPA.
a. Categories of Personal Information about you that we Collect and Disclose . The following is a list of categories of Personal Information (as defined by the CCPA) we have collected and disclosed for a business purpose.
b. Sources of Collection of Personal Information . We have collected Personal Information from the following categories of sources:
We collect, use, and disclose your Personal Information in accordance with the specific business purposes below:
c. Use of your Personal Information . We collect, use, and disclose your Personal Information in accordance with the specific business purposes below:
d. Disclosure of your Personal Information to Third Parties
With respect to the categories of Personal Information identified above in Section 1, we disclose your Personal Information to the following categories of third parties:
We do not use or disclose sensitive personal information for purposes which would require us to offer consumers the right to limit under the CCPA.
e. Collection and Sale of your Personal Information to Other Parties
We do not sell your Personal Information.
f. Retention
We take measures to delete your Personal Information or keep it in a form that does not permit identifying you when this information is no longer necessary for the purposes for which we process it, unless we are required by law to keep this information for a longer period. When determining the retention period, we take into account various criteria, such as the type of products and services requested by or provided to you, the nature and length of our relationship with you, possible re-enrolment with our products or services, the impact on the services we provide to you if we delete some information from or about you, mandatory retention periods provided by law and the statute of limitations.
g. Your Privacy Rights
If you are a California resident, you may exercise the following rights.
Submit Requests. To exercise your rights under the CCPA email us at ekataprivacyanddataprotection@mastercard.com or call our toll-free number: +1 (855) 927-1072.
Authorizing an Agent. If you are acting as an authorized agent to make a request to know, delete, correct, or opt out on behalf of a California resident, email us at ekataprivacyanddataprotection@mastercard.com or call our toll-free number: +1 (855) 927-1072. Please note that we will require you to attach a written authorization signed by the resident whose Personal Information will be subject to the request.
h. CCPA Metrics
Each calendar year, we compile the various metrics describing how we have complied with requests to delete, access, and correct. To view these metrics please visit the “ My Data” portal.