By agreeing to an Order or other Documentation incorporating these terms of service (“Terms of Service” or this “Agreement”) or otherwise accessing or using the products and services provided by the Mastercard Entity ("Mastercard") in the Order, Customer agrees to the terms and conditions set forth herein. Capitalized terms shall have the definitions ascribed to them below.
Mastercard may modify these Terms of Service as provided in Section 33 from time to time.
Mastercard and Customer may be referred to herein individually as a “Party,” and collectively, as the “Parties.”
“Affiliate” means, in relation to a Party, any other entity that directly or indirectly Controls, is Controlled by, or is under common Control with that Party from time to time. “Control,” for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
“Agreement” also referred to sometimes as “Principal Agreement” means these Terms of Service and any Order(s) or other Documentation entered into that incorporate(s) these Terms of Service, including all referenced documents, and all associated amendments and addenda.
“Business Purpose” (or “Purpose”) means the provision and use of the Services, and use of Personal Data by each of Mastercard and Customer, as described in Section 2(a) and (b) of this Agreement.
“Confidential Information” has the meaning provided in Section 12(a).
“Customer” means the entity or entities that has created an account, executed, or agreed to an Agreement, Order or other Documentation incorporating these Terms of Service, or otherwise accesses or uses Mastercard’s products and services.
“Customer Data” means the information submitted by or for Customer to the Services.
“Data Subject” has the meaning provided in the Data Processing Agreement.
“Data Processing Agreement” or “DPA” means that certain Data Processing Agreement that shall, unless otherwise agreed, be made a part of this Agreement. The Data Processing Agreement is described in Section 17 hereof.
“Documentation” means all specifications, documentation, guidelines, program guides, implementation guides, manuals, announcements, pricing bulletins and other pricing arrangements, an Order, Data Processing Agreement, the Mastercard Direct Services Manual and Technical Specifications Guide, as may be amended from time to time (the “DS Guide”), release notes, reference guides or other documents relating to the Services, as amended and updated from time to time, which are provided by Mastercard to Customer. Documentation is Confidential Information of Mastercard, and all rights not expressly granted to Customer are retained by Mastercard. Upon expiration or termination of the Services, Customer shall promptly return to Mastercard or destroy all Documentation. The obligations, restrictions, and limitations of Documentation shall survive the expiration or termination of the Services.
“Fees” has the meaning provided in Section 5.
“Insights” means data that Mastercard derives, or generates from its analysis of Customer Data and/or Outcome Data, as applicable. Examples of Insights include the number of times a data element has been queried in a period of time (velocity) or the last time a data element has been seen (recency). Insights do not constitute Customer Data.
“Intellectual Property Right(s)” means any and all now or hereafter known tangible and intangible (i) rights associated with works or authorship throughout the world, including copyrights or works of copyright, moral rights, and mask-works; (ii) Marks and similar rights; (iii) trade secret rights; (iv) patents designs, algorithms, and other industrial property rights; (v) all other intellectual and industrial property rights of every kind and nature throughout the world and however designated (including domain names, logos, “rental” rights, and rights to remuneration), whether arising by operation of law, contract, license, or otherwise; and (vi) all registrations, initial applications, renewals, extensions, continuations, divisions, or reissues thereof currently or hereafter in force (including any derivative rights in any of the foregoing).
“Mastercard Data” means data that Mastercard processes or otherwise makes available to Customer through the Services or pursuant to an Order. Mastercard Data includes but is not limited to information from publicly available sources, third-party data providers, and Insights.
“Mastercard Entity” means Mastercard International Incorporated or its applicable Affiliate as designated in the Order; provided however, Orders executed prior to August 7, 2026 where the Customer contracting entity is in the United States, the Mastercard Entity is Mastercard International Services, Inc.
“Mastercard Intellectual Property” means (i) these Terms of Service and any and all software, websites, programs, and other applications provided or made available by Mastercard in connection with any of the foregoing, and the user experience and Look and Feel of any of the foregoing; (ii) all Documentation, computer software, processes, procedures, systems, sales materials, technical materials, checklists, and any other documentation issued or made available by Mastercard; (iii) the Mastercard Marks; (iv) Mastercard Data; and (v) any and all improvements, enhancements, modifications, alterations, or derivative works of or to any of the items mentioned in (i), (ii), and (iii) herein. For purposes of this definition, “Look and Feel” refers to the elements of graphics, design, organization, presentation, layout, user interface, navigation, trade dress, and stylistic convention (including the digital implementation thereof).
“Marks” means trademarks and service marks (whether registered or at common law), trade names, business names, logos, sounds, animations, haptics, visual depictions, symbols and Internet domain names, or any abbreviation or contraction thereof.
“Order” means a document or other form of agreement entered into between Customer and Mastercard Entity, that specifies the Services to be provided by Mastercard or its Affiliates.
“Outcome Data” has the meaning provided in Section 11.
“Person” means and includes any individual, partnership, joint venture, corporation, company, bank, trust, unincorporated organization, government, or any department, agency, or instrumentality thereof.
“Personal Information” or “Personal Data” has the meaning provided in the Data Processing Agreement.
“Privacy and Data Protection Law” has the meaning provided in the Data Processing Agreement.
“Processing of Personal Data” (or “Processing/Process”) has the meaning provided in the Data Processing Agreement.
"Query" has occurred when Customer submits a request for information to the Service, and the Service returns a result to the Customer, regardless of the relevance of that result to Customer. A batch Query (or file) that is designed to return multiple unrelated responses will be charged as if Customer submitted multiple Queries.
"Seat License" entitles one human User to access the Services. Login credentials may not be shared.
“Services” means those global identity verification products and services provided by Mastercard to Customer under an Order. “Services” exclude Mastercard Data.
“State Privacy Laws” has the meaning provided in the Data Processing Agreement.
“User” means an individual who is authorized by Customer to access or use the Services, and who has been provided a user id and password, or other account credential. Users may include employees, contractors, and agents of Customer.
(a) Mastercard’s Business Purpose. In accordance with this Agreement, Mastercard processes Personal Data for the following Business Purposes: to provide the Services to Customer pursuant to this Agreement, to improve and develop Mastercard’s products and services, to enable fraud detection and prevention, , and to ensure compliance with applicable laws; and
(b) Customer’s Business Purpose. Customer may use the Services and process Personal Data for the following Business Purpose: to receive and use Mastercard Data in the context of the Services for identification verification, and in order to detect, prevent, and/or combat fraud.
(c) Provision of Service.
(i) Mastercard will provide application programming interface(s) or web portal access to enable Customer’s access to the Services and Mastercard Data. Mastercard provides certain Services and Mastercard Data by employing machine learning techniques that identify patterns in data using algorithmic models. These models leverage Mastercard Data and Customer Data. When Customer submits Customer Data to the Services, Mastercard may analyze, retain, and otherwise Process Customer Data in conjunction with Mastercard Data and other customers’ data to create Insights to provide results to Customer’s Queries or the queries of other customers, and for any other purpose permitted by law.
(ii) In order to access the Services, Customer must enter into an Order and Customer and/or its Users may be required to create user accounts. Customer agrees that the account information provided will be accurate and complete at the time it is provided and will be maintained and updated to keep it accurate and complete. Mastercard may contact Customer and require confirmation of account information before first use or continued use of the Services. Mastercard reserves the right to terminate any licenses granted hereunder and to refuse to provide access to the Services if, in Mastercard’s sole reasonable discretion, Mastercard determines that any account information is, or appears to be, inaccurate, incomplete, or fraudulent.
(iii) If Customer accesses the Services on a per-Query basis, Customer may be charged either for the monthly minimum number of Queries to which Customer agreed or the actual number of Queries performed, whichever is greater. If Customer accesses the Services on a per-seat basis, Customer will instead by charged for the number of Seat Licenses issued to your account during the applicable billing period. Mastercard may limit or suspend accounts of customers who have purchased Seat Licenses whose accounts are used to submit Queries to the Services with a volume or velocity that is inconsistent with the typical query volume or velocity of a single human user, in Mastercard’s sole discretion.
(iv) If Customer engages in a preliminary data evaluation or integration test for the Services, either through an Order or by separate agreement, the start date of the paid Services ordered by Customer following such evaluation or test will be as provided in the Order. Additional terms and conditions for such evaluation or test may appear on an Order, in a separate agreement executed for this purpose, or as otherwise agreed by the Parties in writing.
(a) The term of the Agreement will commence on the Effective Date provided in the Order(s) incorporating these Terms of Service and will continue until the expiration or termination of such Order(s) (collectively, the “Term”). To the extent that Customer is afforded access to Services hereunder and has not completed an Order for same, this Agreement shall commence on the date Customer begins accessing the Services and shall continue until superseded by an Order or until Mastercard chooses in its discretion to revoke access to the Services.
(b) Either Party may terminate an Order upon thirty (30) days’ notice, if the other Party has breached a material obligation, representation, or warranty under these Terms of Service with respect to the provision or use of the Service or Mastercard Data as provided for herein and fails to cure such breach within the thirty (30) days of receiving notice of such breach. Either Party may terminate an Order governed by these Terms of Service if the other Party (i) becomes insolvent; (ii) is declared bankrupt; (iii) is placed under receivership; (iv) makes an assignment for the benefit of creditors; (v) commences any proceedings for the winding up of its business, dissolution, or liquidation; or (vi) ceases to pay its debts as they become due. Additionally, Mastercard may terminate or suspend this Agreement or an Order, upon thirty (30) days’ notice in the event that it reasonably believes that Customer has used or accessed the Services and/or Processed Personal Data in contradiction of or beyond the scope of the Business Purpose set forth in Section 2(b) above.
(c) In the event that Customer terminates the Agreement in accordance with Section 4(b), Mastercard will refund any prepaid fees covering the remainder of Customer’s annual subscription after the effective date of termination. In the event that Mastercard terminates for same, Customer shall pay any unpaid fees covering the remainder of the Term to the extent permitted by applicable law. In no event will termination relieve Customer of its obligation to pay any fees payable to Mastercard for the period of the Term prior to the effective date of termination.
(d) At any time, Mastercard may terminate or suspend an Order, in its sole discretion (i) upon ninety (90) days’ notice, if Mastercard discontinues the applicable Service in on or more of the countries in the Territory; or (ii) effective immediately and without prior notice, if required by applicable law or the relevant governing authority, if Mastercard is required by such law or governing authority to cease providing such Service to such Customer or in one or more countries in the applicable Territory; (iii) Mastercard has reason to believe that not terminating or suspending such participation would be harmful to Mastercard’s goodwill or reputation; or (iv) if Mastercard has received a claim or notice alleging that such Service infringes or violates a third party’s Intellectual Property Right.
(e) Mastercard may terminate this Agreement and any applicable Order, upon written notice to Customer, if Customer has not used the Services within twelve (12) months following the Effective Date.
(f) The Parties agree that, unless otherwise agreed upon by the Parties or incorporated into a separate agreement, the Data Processing Agreement is terminated upon the termination of this Agreement.
(g) Termination or expiration of the Agreement pursuant to this Section 4 shall not relieve either Party of any obligation accrued through the date of termination or expiration.
(a) Customer shall pay to Mastercard the fees (the “Fees”) specified in an applicable Order. Mastercard will provide Customer with at least sixty (60) days’ prior notice of any increase to Fees, which increases will take effect at renewal. Unless otherwise provided herein, payment obligations are non-cancellable, and fees paid are non-refundable. Minimum monthly or annual commitments prepaid cannot be decreased during the Term or rolled into any renewal Term. If Customer provides its credit card information, Customer authorizes Mastercard to charge said credit card for the Services specified in an applicable Order. To the extent that terms regarding fees, payment, and contract duration in any Order conflict with this Agreement, the terms of such Order shall control. Except where otherwise specified in an applicable Order, all invoices issued by Mastercard shall be payable by Customer within thirty (30) days of the invoice date.
(b) Customer acknowledges that the Fees are exclusive of any applicable taxes and/or duties. Customer is responsible for any taxes and/or duties that may be levied on the provision of the Services. Customer will not be responsible for any taxes levied on Mastercard’s income.
(c) If Customer owes any Fees under an Order that are more than forty-five (45) days overdue, Mastercard may, without limiting any other rights or remedies, accelerate Customer’s unpaid obligations to immediately due and payable. Mastercard reserves the right to suspend Services until such amounts are paid in full or to terminate the Agreement for nonpayment.
(d) If the price stated on an Order is determined by Mastercard to be erroneous, in Mastercard’s sole discretion, Mastercard shall not be obligated to offer Customer access to the Services at such price. Mastercard will notify Customer of such error and afford Customer the opportunity to cancel the Order and obtain a refund if payment has already been made.
(e) Mastercard or its Affiliate may invoice Customer.
(a) As between Mastercard and Customer, Customer owns and retains all right, title and interest in and to Customer Data. Customer grants Mastercard a limited, royalty-free, non-exclusive, worldwide right and license to store, access, use, copy and create derivative works from the Customer Data. Additionally, Customer acknowledges and agrees that, Mastercard may generate or derive Insights from Customer Data. As between Customer and Mastercard, Mastercard will own all rights, title, and interest in and to Mastercard Data.
(b) Customer agrees that Mastercard may Process Customer Data for as long as reasonably necessary to provide identity verification and fraud detection services through the Services. Mastercard stores Customer Data in a securely encrypted format for a longer period of time to enable Mastercard to bill for the Services, to provide customer service to Customer, and to apply machine learning techniques that help Mastercard identify patterns in the data. When Mastercard Processes Customer Data to generate and analyze Insights, such data (i) will be pseudonymized through cryptographic hashing, (ii) will be aggregated with data from other customers of the Services, and (iii) will not be made available to any other customer. For clarity, Insights provided to Customer through the Services will not include any identifiers indicating other customers that are the source of Insights. Mastercard shall have the right to transfer Customer Data to a Mastercard Affiliate(s) as a third party if required for the performance and purposes hereof.
(c) Notwithstanding anything to the contrary in this Agreement, Customer authorizes Mastercard to:
(i) Process, including, where necessary, to aggregate, or anonymize, Customer Data to effectuate Mastercard’s Business Purpose;
(ii) Use Customer Data for the following business purposes and in compliance with all applicable laws: (a) in connection with Licensor or its Affiliate's internal operations, including for legal, accounting, or auditing purposes; (b) to maintain and improve the quality of Licensor or its Affiliate's services; (c) to develop, improve and deliver existing and new products or services; (d) to secure Licensor’s personnel, products, or systems and to conduct risk management, including fraud monitoring and prevention, and (e) with the consent of the data subject where such consent is necessary. With respect to each of the activities in this Section 8(c)(ii), Licensor will not disclose any Customer Data to any third party unless such Customer Data does not identify any individual or Customer; and
(iii) Anonymize Customer Data, and aggregate it with other data collected by Mastercard, to create compilations, reports, analyses and insights, provided that such compilations, reports, analyses and insights do not identify, or attempt to identify, any individual or Customer.
(d) As between Mastercard and Customer, Mastercard owns all right, title and interest in and to the Services and the Mastercard Data, and any enhancements or modifications thereto. No rights are granted to Customer hereunder other than as expressly set forth herein. Mastercard
(e) Customer hereby grants Mastercard a worldwide, perpetual, irrevocable, royalty-free license to use and incorporate into the Services any suggestion, enhancement request, or other feedback provided by Customer relating to the Services.
(a) Customer shall be responsible for its compliance and its Affiliates’ compliance with this Agreement and all Orders. Customer will use best efforts to prevent unauthorized access to the Services or Processing of Mastercard Data, and Customer will notify Mastercard without undue delay and in any event no later than 24 (twenty-four) hours after becoming aware of any such unauthorized access or Processing. Customer will use the Services and Mastercard Data only to the extent permitted by this Agreement and applicable Order(s). Customer is solely responsible for ensuring that its use of the Services and Mastercard Data, including the Customer’s provision of Customer Data to Mastercard as contemplated in this Agreement, does not violate any laws of the applicable jurisdictions in which Customer does business and from which its use of the Services originates (collectively, the “Territory”), in particular any Privacy and Data Protection Law. For the avoidance of doubt, Customer will not collect, provide or make available to Mastercard any Customer Data that is not collected or stored in accordance with applicable law and Customer’s privacy policy (or the privacy policy of Customer’s customers, if applicable) .Any use of the Services in breach of this Agreement by Customer, or its Affiliates, may result in Mastercard’s immediate suspension of the Services.
(b) Customer will not: (i) make any Services available to anyone other than Customer, its Affiliates, and Users; (ii) use the Services for the benefit of anyone other than Customer or its Affiliates; (iii) falsify or alter any unique identifier assigned to Customer, or otherwise obscure or alter the source of queries to the Services; (iv) permit direct or indirect access to or use of any Services in a way that circumvents any usage limits; (v) reproduce, modify, distribute, disassemble, reverse engineer or create derivative works based on any portion of the Services; (vi) violate or attempt to violate the security of the Services, or introduce any malicious code into the Services; (vii) use the Services to build a competitive product or service or in any way not permitted by this Agreement; or (viii) submit Customer Data to the Services that contain any information deemed “sensitive” under applicable law (including, without limitation, government identification numbers, financial account information, or information related to children).
(c) Any Affiliate of Customer must (i) execute a separate Order with Mastercard prior to accessing the Services or any Mastercard Data, or (ii) be expressly identified in Customer’s Order, in each case to enable Mastercard to conduct due diligence and maintain visibility over all Customer Affiliates accessing Mastercard Data.”.
(d) Customer will only use the Services as permitted by the terms of this Agreement and applicable laws. In particular, Customer will use the Mastercard Data for identity verification and fraud detection and prevention use cases only, and will not: (i) use the Mastercard Data for marketing purposes; (ii) use the Mastercard Data in violation of any applicable law, rule, or regulation or in violation of any third-party right; (iii) store the Mastercard Data for purposes other than those expressly permitted hereunder; (iv) use the Mastercard Data in conjunction with illicit activities; (v) store or cache the Mastercard Data to avoid making additional Queries to the Services; (vi) merge stored Mastercard Data with other data unless it is coded or tagged to indicate Mastercard as its source; or (vii) use the Services to access Personal Data other than the Personal Data of the individual(s) for whom identity verification and fraud prevention is being conducted (i.e., intentionally accessing the Personal Data of related individuals for a purpose other than fraud prevention).
(e) Customer acknowledges that the Services are not provided by a “consumer reporting agency” as that term is defined in the Fair Credit Reporting Act (“FCRA”) and the Mastercard Data do not constitute “consumer reports” as defined in the FCRA. Accordingly, the Mastercard Data may not be used as a factor in determining eligibility for credit, insurance, employment or any other purpose in which a consumer report may be used under the FCRA (or any similar consumer credit law in the United States of America or otherwise). For the avoidance of doubt, Customer agrees that it shall not use the Services to assess, determine or verify the creditworthiness of any individual(s).
(f) Customer acknowledges that the Services (i) are only one component of a range of risk management activities that Customer undertakes; (ii) are services that Customer cannot undertake itself; and (iii) do not affect or replace a critical operation of Customer or expose Customer to a material operational risk (i.e., without limitation, weakness or failure of the Services will not prevent Customer from operating or meeting its regulatory obligations). Mastercard shall not have, and hereby disclaims, any and all liability that Customer may face as a result of Customer’s non-compliance with regulatory obligations relating to outsourcing.
(a) Customer shall provide results data to Mastercard regarding all Queries assesses through the Services by Customer via API or SFTP (batch file), and such outcome data shall consist of the following sets of data elements: outcome, transaction ID and API Key (the “Outcome Data”).
(b) Customer will provide Outcome Data to Mastercard within sixty (60) days of the Effective Date, and every quarter thereafter
(c) Customer grants Mastercard and its Affiliates a non-exclusive, non-transferable, limited license to analyze and use such Outcome Data solely to improve the capabilities of the Services. Mastercard shall not disclose Outcome Data, in whole or in part, to any non-Affiliate third party.
(d) Customer shall own all rights and title in and to the Outcome Data; provided, that Mastercard and its Affiliates shall have the perpetual right to use Insights derived from the Outcome Data within the Services.
(e) Customer acknowledges that Mastercard has priced its products in reliance on Customer’s provision of the Outcome Data, and that it forms an essential basis for the pricing.
(f) Although Customer will provide the Outcome Data in a careful and workmanlike manner, Customer makes no representations or warranties, express or implied, with respect to the accuracy or completeness of the Outcome Data.
(a) Definition. The term “Confidential Information” means all information disclosed by one Party (“Discloser”) to the other Party (“Recipient”) (in writing, orally, or in any other form) that is identified at the time of disclosure as confidential or should have reasonably been known by the Recipient to be confidential (including, without limitation, trade secrets and unpublished patent applications, and for Mastercard, the Mastercard Intellectual Property or any data and information contained therein), together with any documents prepared by the Recipient that contain, otherwise reflect, or, in whole or in part, are generated from such disclosed information. Confidential Information does not include information or material that (i) is now, or hereafter becomes, through no act or failure to act on the part of Recipient, publicly known or available; (ii) is or was known by the Recipient at or before the time such information or material was received from the Discloser, as evidenced by Recipient’s tangible (including written or electronic) records; (iii) is furnished to the Recipient by a third party that is not under an obligation of confidentiality to the Discloser with respect to such information or material; or (iv) is independently developed by the Recipient or on behalf of the Recipient without any use of the Discloser’s Confidential Information.
(b) Protection and Use. During the Term and for a period of three (3) years thereafter, each Party shall take all reasonable measures to protect the confidentiality of the other Party’s Confidential Information in a manner that is at least as protective as the measures that it uses to maintain the confidentiality of its own Confidential Information, but not less than a reasonable standard. Each Recipient shall hold the other Party’s Confidential Information in strict confidence and shall not disclose, copy, reproduce, sell, assign, license, market, transfer, or otherwise dispose of such information, or give or disclose such information to third parties, or use such information for any purpose other than as necessary to fulfil its obligations or exercise its rights under these Terms of Service and the Documentation. Notwithstanding the foregoing, the Recipient may disclose the Discloser’s Confidential Information (i) to employees, consultants, and subcontractors that have a need to know such information, provided that the Recipient shall advise each such employee and consultant of their obligations to keep such information confidential; and (ii) to the extent that Recipient is legally compelled to disclose such Confidential Information pursuant to a subpoena or the order of any governmental authority; provide that, where possible and permitted by applicable law, the Recipient shall give advance notice of such compelled disclosure to the Discloser, and shall cooperate with the Discloser in connection with these efforts to prevent or limit the scope of such disclosure and/or use of the Confidential Information. Mastercard shall ensure that its employees, agents, subcontractors, and sub-processors are subject to a duty of confidentiality with respect to Personal Data provided by Customer.
(c) Return of Confidential Information. Except as otherwise stated in the Documentation, upon termination of the Agreement, the Recipient shall securely destroy all Confidential Information in the Recipient’s possession. Notwithstanding the foregoing, the Recipient is not obligated to destroy Confidential Information (i) commingled with other information of the Recipient if it would be a substantial administrative burden to excise such Confidential Information; (ii) contained in an archived computer system backup made in accordance with the Recipient’s security or disaster recovery procedures; or (iii) required to be retained pursuant to applicable law, regulatory requirements, or post-termination obligations as stated in the Documentation, provided in each case that such Confidential Information remains subject to the obligations of confidentiality herein until its eventual destruction.
(a) Each Party represents and warrants that (i) it is duly organized, validly existing, and in good standing under the laws of the jurisdiction of its incorporation; (ii) it has the full right and power to enter into an agreement governed by these Terms of Service and fully perform its obligations hereunder; and (iii) the execution and delivery of the agreement governed by these Terms of Service and the performance of its obligations hereunder will not violate or conflict with any other agreement to which it is a party.
(b) Customer represents and warrants that both (i) its provision of any Customer Data or Personal Data to Mastercard in connection with these Terms of Service; and (ii) the use, analysis, and/or Processing of such items by Mastercard to perform and/or provide the Services, are, collectively, permitted under (x) all applicable laws, regulations, and regulatory guidance; and (y) the terms of Customer’s contracts with, notices to, or other consents from, its customers, contractors, suppliers, or other third parties.
(a) Mastercard Indemnification Obligation. Mastercard shall indemnify, defend (at its option, in accordance with this Section), and hold the Customer, its Affiliates, and its and their respective directors, officers, employees, agents, and representatives, harmless from and against any third-party claim, and shall pay any losses, costs, liabilities, demands, damages, and expenses including reasonable attorneys’ fees (collectively, “Losses”) incurred as a result of any such third party claim, arising out of or relating to (except to the extent caused by a Customer’s breach of any of its obligations, representations, or warranties hereunder) (i) any actual or alleged infringement, violation, or misappropriation of any patent, trademark, or copyright to the extent based on any Mastercard Intellectual Property, and/or any equipment, processes, and other resources used by Mastercard in connection with the Customer Data (other than any technology, equipment, processes, and other resources provided by the Customer); or (ii) Mastercard’s (x) material breach of any of its obligations, representations, and warranties hereunder and in the applicable Documentation; or (y) gross negligence or wilful misconduct in the performance of its obligations under these Terms of Service and the applicable Documentation.
(b) Customer Indemnification Obligation. Customer shall indemnify, defend (at its option, in accordance with this Section), and hold Mastercard, its Affiliates, and its and their respective officers, directors, employees, agents, and representatives, harmless from and against any third party claim, and shall pay any Losses incurred as a result of any such third party claim, arising out of or relating to (except to the extent caused by Mastercard’s breach of any of its obligations, representations, or warranties hereunder) (i) any actual or alleged infringement, violation, or misappropriation of any patent, trademark, or copyright to the extent based on any Customer Data, and/or any equipment, processes, and other resources used by the Customer in connection with the Mastercard Intellectual Property (other than any technology, equipment, processes, and other resources provided by Mastercard); or (ii) the Customer’s (x) material breach of any of its obligations, representations, and warranties hereunder, including without limitation in the event that Customer’s use of the Services is found to violate consumer protection law, age discrimination law, human rights law, or other unlawful discrimination law; or (y) gross negligence or wilful misconduct in the performance of its obligations under these Terms of Service, including without limitation in the event that Customer’s misuse of Personal Data results in any fines or penalties.
(c) Indemnification Process. If a Party entitled to indemnification hereunder (the “Indemnified Party”) becomes aware of any claim that it believes is subject to indemnification hereunder, the Indemnified Party will give the other Party (the “Indemnifying Party”) prompt notice thereof. Such notice (the “Claim Notice”) shall (i) provide the basis on which indemnification is being asserted; and (ii) be accompanied by copies of all relevant pleadings and other papers related to the claim and in the possession of the Indemnified Party. The Indemnifying Party may assume, at its sole option, control of the defense of the claim by sending notice of such assumption to the Indemnified Party on or before thirty (30) days after receipt of the Claim Notice to acknowledge responsibility for the defense of such claim and undertake, conduct, and control, through reputable independent counsel of its own choosing and at the Indemnifying Party’s sole cost and expense, the settlement or defense thereof. The Indemnified Party shall cooperate, at the expense of the Indemnifying Party, with the Indemnifying Party and its counsel in the defense, and the Indemnified Party shall have the right to participate, at its own expense, in the defense of such claim. The Indemnifying Party shall obtain the Indemnified Party’s consent to any compromise or settlement of a claim to the extent such compromise or settlement affects the rights of such Indemnified Party, which consent shall not be unreasonably withheld or delayed.
NOTWITHSTANDING ANY OTHER PROVISION TO THE CONTRARY SET FORTH IN THESE TERMS OF SERVICE, EACH PARTY SHALL NOT BE LIABLE UNDER ANY LEGAL THEORY, INCLUDING TORT, CONTRACT, STRICT LIABILITY OR OTHERWISE, FOR ANY SPECIAL, INDIRECT, INCIDENTAL, CONSEQUENTIAL, PUNITIVE OR EXEMPLARY DAMAGES, INCLUDING FOR LOSS OF PROFITS, DATAOR GOODWILL, REGARDLESS OF WHETHER SUCH PARTY KNEW OR SHOULD HAVE KNOWN OF THE POSSIBILITY OF SUCH DAMAGES.
EACH PARTY AGREES THAT, IN RELATION TO THE PROCESSING OF PERSONAL DATA FOR ITS OWN PURPOSES, IT IS FULLY LIABLE TOWARDS INDIVIDUALS FOR THE ENTIRE DAMAGES RESULTING FROM A VIOLATION OF PRIVACY AND DATA PROTECTION LAW OR OF THIS AGREEMENT. THE PARTIES AGREE THAT IF MASTERCARD HAS PAID COMPENSATION, DAMAGES OR FINES, MASTERCARD IS ENTITLED TO CLAIM BACK FROM CUSTOMER THAT PART OF THE COMPENSATION, DAMAGES OR FINES CORRESPONDING TO CUSTOMER’S PART OF RESPONSIBILITY FOR THE COMPENSATION, DAMAGES OR FINES.
NOTWITHSTANDING ANY OTHER PROVISION TO THE CONTRARY SET FORTH IN THESE TERMS OF SERVICE, AND EXCLUDING LIABILITY FOR NON-PAYMENT BY THE CUSTOMER OF FEES DUE UNDER THE APPLICABLE DOCUMENTATION, THE MAXIMUM AGGREGATE LIABILITY OF EACH PARTY AND ITS AFFILIATES OVER THE TERM FOR THE PROVISION THE SERVICES (AS SET FORTH IN THE APPLICABLE DOCUMENTATION) ARISING OUT OF OR RELATING TO SUCH SERVICES, EITHER INDIVIDUALLY OR IN A BUNDLE AS SET FORTH IN THE APPLICABLE DOCUMENTATION (INCLUDING, WITHOUT LIMITATION, INDEMNIFICATION OBLIGATIONS HEREUNDER) SHALL BE THE GREATER OF TWO HUNDRED FIFTY THOUSAND DOLLARS ($250,000) OR THE NET FEES PAID OR PAYABLE FOR THE SERVICES BY THE CUSTOMER UNDER THE APPLICABLE DOCUMENTATION DURING THE TWELVE (12) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO LIABILITY.
Notwithstanding the foregoing, Mastercard Europe SA is the counterparty solely with respect to Annex 2 of the Data Processing Agreement (the “EU Addendum”) regardless of Customer’s location.
|
|
|
|
|
Mastercard International Services, Inc. |
State of New York, US |
Westchester County, NY, USA |
|
Mastercard International Inc. |
State of New York, US |
Westchester County, NY, USA |
|
Mastercard Brasil Soluções de Pagamento Ltda. |
Brazil |
São Paulo, Brazil |
|
Mastercard Cono Sur S.R.L. |
Argentina |
Buenos Aires, Argentina |
|
Mastercard Europe SA |
Belgium |
Waterloo, Belgium |
|
Mastercard Middle East Africa FZ-LLC |
Singapore |
Singapore |
|
Mastercard Asia/Pacific Pte. Ltd. |
Singapore |
Singapore |
(a) Each Party hereby guarantees that it is neither on any sanctions list of the European Union, the United States, or the United Nations, nor are they subject to a corresponding embargo, and that the execution of this Agreement does not otherwise violate export control regulations during the term of this Agreement. The Parties shall not engage in dealings, directly or indirectly, with any entity or person or in any jurisdiction subject to European Union, the United States, or the United Nations sanctions regulations.
(b) The Parties represent, warrant and covenant that each of it and its staff, subcontractors, agents and other third parties acting on its behalf: (a) is not named on any U.S. Department of Treasury Office of Foreign Asset Control Sanctions lists or any applicable foreign sanctions lists; (b) shall not, directly or indirectly, access, use, sell, export, reexport, transfer, divert, or otherwise dispose of all or any part of the Services or Documentation to any country (or national thereof) that is subject to antiterrorism controls or U.S. embargo, or to any other person or entity or destination prohibited by the laws of the U.S. or the laws of the Territory or any other applicable jurisdiction, without obtaining, at its own expense, prior authorization from the competent government authorities as required by those laws.
(c) The Parties shall not engage in dealings, directly or indirectly, with any entity or person or in any jurisdiction subject to U.S. OFAC sanctions regulations. Each Party represents and warrants that it is currently not on any OFAC List, nor on any similar restricted party listings, including those maintained by other governments pursuant to applicable United Nations, regional or national trade or financial sanctions.
(d) The Parties shall comply with all trade and economic sanctions programs relevant to where they do business, including trade and economic sanctions maintained by the Office of Foreign Assets Control (“OFAC”) and similar laws of the countries where the Parties are located. The Parties shall not engage in any conduct that would cause the other Party to violate applicable sanctions programs. The Parties shall notify the other party immediately if it becomes aware that it, its subcontractors, or related parties engage in activity prohibited by applicable sanctions. To the extent applicable, the Parties shall comply and shall ensure that each of its subcontractors and personnel complies, with all applicable laws (e.g., anti-bribery, corruption, export controls, sanctions) in connection with this Agreement. Each Party agrees to comply with all applicable laws and regulations in connection with this Agreement.
(e) Customer acknowledges that the Services, or a portion thereof, are subject to the Export Administration Regulations, 15 C.F.R. Parts 730-774, of the United States and may be subject to other applicable country export control and trade sanctions laws (“Export Control and Sanctions Laws”). Customer shall not, and shall not permit any of its end users of the Services, to access, use, export, re-export, divert, transfer, or disclose any part of the Services or any related technical information or materials, directly or indirectly, in violation of any applicable export control or trade sanctions law or regulation. Company represents and warrants that: (i) Company and Company’s end users (A) are not citizens of, or located within, a country or territory that is subject to U.S. trade sanctions or other significant trade restrictions (including without limitation Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk and Luhansk regions of Ukraine) and that Company and Company’s end users will not access or use the Services, or export, re-export, divert, or transfer the Services, in or to such countries or territories; (B) are not persons, or owned 50% or more, individually or in the aggregate by persons, identified on the U.S. Department of the Treasury’s Specially Designated Nationals and Blocked Persons List or Foreign Sanctions Evaders Lists; and (C) are not persons on the U.S. Department of Commerce’s Denied Persons List, Entity List, or Unverified List, or U.S. Department of State proliferation-related lists; and (ii) Company and Company’s end users located in China, Russia, or Venezuela are not Military end users and will not put the Services to a Military end user, as defined in 15 C.F.R. 744.21. Company is solely responsible for complying with the Export Control and Sanctions Laws and monitoring them for any modifications.
(a) Australia. Customer agrees that the Services will only be used in accordance with the Age Discrimination Act 2004 and agrees to indemnify Mastercard and its Affiliates against any claims for age discrimination arising from Customer’s use of the Services.
(b) Canada. The prohibitions of Section 9(h) hereof shall also include, without limitation, any reliance by Customer on the Services to inform decision-making relating to: (i) the extension of credit; (ii) entering into or renewing tenancy agreements; (iii) employment purposes; (iv) underwriting of insurance involving consumers; or (v) assessing eligibility for any benefits. The fraud scoring provided hereunder is an automated tool to support Customer’s own fraud-prevention-related due diligence.
(c) China. Customer warrants that its notice to Data Subjects pursuant to this Agreement shall have specified that Personal Data would be disclosed to Mastercard (including Mastercard’s contact information), the categories of Personal Data shared, and the purposes of the sharing. Consent for both data sharing and Processing by Mastercard shall have been obtained by Customer at collection.
(d) Germany. Customer agrees that it shall not rely on any result delivered via the Services that is calculated solely on the basis of an individual’s physical address in order to determine whether or not to contract with such individual for any reason. Further, Customer agrees to inform Data Subjects within Customer Data specifically about the potential use of their address data for identity verification and fraud prevention assessment.
(e) Hong Kong. Customer agrees that all cybersecurity measures employed by Mastercard through its privacy and security policies and programs are commercially reasonable and satisfactory to Customer.
(f) India. Customer warrants that it shall not: (i) use the Services as a substitute for its know-your-customer compliance or decisioning; (ii) rely on the Services when making any decision regarding the extension of credit or a loan; or (iii) provide Mastercard with any credit information. Customer agrees to indemnify Mastercard and its Affiliates for any claims that may arise as a result of Customer providing Mastercard or an Affiliate with any credit information. In addition, Customer warrants that it has complied with the Information Technology (Amendment) Act, 2008, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
(g) Indonesia. Customer shall have notified and/or obtained any relevant acknowledgments and/or approvals from relevant regulators or authorities as required in order to receive and use this Services from Mastercard. Customer shall, upon request from Mastercard, promptly provide any such assessments, acknowledgments and/or approvals to Mastercard.
(h) Philippines. Customer agrees to indemnify and hold Mastercard harmless for any claims or investigations arising out of the use of the Services by Customer or its employees or agents is in violation of this Agreement and/or applicable law.
(i) South Africa. Customer warrants that it is not subject to consumer protection laws applicable only to small businesses. For the avoidance of doubt, Customer has an annual turnover greater than ZAR 2 million.
(j) Turkey. Customer agrees that the Services will only be used in accordance with the Law on Human Rights and Equality Institution of Turkey and agrees to indemnify Mastercard and its Affiliates against any claims for age discrimination arising from Customer’s use of the Services.
(k) Ukraine. Customer warrants that it does not and will not rely exclusively on the Services for Data Subject identification and verification purposes apart from in direct connection with fraud prevention. Customer agrees that the Services are advisory and are provided for informational purposes only.