We collect personal data about individuals from various sources described below. Where applicable, we indicate whether and why individuals must provide us with personal data, as well as the consequences of failing to do so.
A. Information that we collect about Developers and their personnel
|Category of Data||Description|
B. Information that we collect from private and publicly accessible sources
C. Information collected via automated means
When you access our websites or use our mobile applications, we, our service providers, and our partners may automatically collect information about you, your computer or mobile device, and activity on our websites or mobile applications, which may include the Technical Data and Usage Data set out above. Certain products or services that we provide or which developers may incorporate into their websites or mobile applications may automatically collect additional information, as may be further described in a separate privacy notice.
Our service providers and business partners may collect this type of information over time and across third-party websites. This information is collected via various mechanisms, such as via cookies, web beacons, embedded scripts, through our mobile applications, and similar technologies. This type of information may also be collected when you read our HTML-enabled emails. Please refer to our Cookies Notice for more details. You can choose to disable cookies or to opt out of the use of your browsing behaviour for purposes of targeted advertising. For opt out instructions, please review the “Targeted online advertising” portion of the “Your Choices” section of this Privacy Notice.
D. Sensitive personal data
In limited circumstances and when permitted by law, we may collect a developer’s and/or their employee’s biometric data to confirm a developer’s and/or their employee’s identity, such as when they authenticate a payment or sign into their Fiserv device using their fingerprint.
Outside of these contexts or otherwise as we specifically request, we ask that you not provide us with any sensitive personal data (meaning information revealing racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, genetic, health, or biometric information, information about sex life or sexual orientation, or criminal convictions or offenses) through our websites or mobile applications, or otherwise to us.
We use your personal data for the purposes of:
Providing our products and services, which includes:
- Operating, evaluating, maintaining, improving, and providing the features and functionality of our products and services, including the Portal
- Providing you with access with our Application Programming Interfaces
- Managing our relationship with you or your company (including identifying you and digital rights management)
- Carrying out our obligations, and exercising our rights, under our agreement with you or your company
- Communicating with you regarding your relationship with us, including by sending you service-related emails or messages (e.g., messages regarding account verification, changes or updates to the functionality of our products or services, technical and security notices and alerts, and support and administrative messages)
- Personalizing the manner in which we provide our products and services, including the Portal
- Administering and protecting our business
- Providing support and maintenance for our products and services, including responding to your service-related requests, questions, and feedback
For research and development
We use the information we collect for our own research and development purposes, which include:
- Developing or improving our products and services
- Developing and creating analytics and related reporting, such as regarding industry and fraud trends
- We may use your personal data to form a view on what products or services we think you may want or need, or what may be of interest to you.
- You may receive marketing communications from us if you have actively expressed your interest in making a purchase or have made a purchase from us and, in each case, you have not opted out of receiving that marketing, to the extent permitted by applicable law.
- Where required by law, we will get your express opt-in consent before we share your personal data with any company outside the Fiserv group for marketing purposes.
- You can ask us or third parties to stop sending you marketing messages at any time by contacting us using the contact information below or clicking on the opt-out link included in each marketing message.
- Should you choose to opt out of receiving our marketing messages, we will continue to carry out our other relevant activities using your personal data, including sending non-marketing messages.
Complying with law
We use your personal data as we believe necessary or appropriate to comply with applicable laws, lawful requests and legal process, such as to respond to subpoenas or requests from government authorities.
Compliance, fraud prevention and safety
We use your personal data as we believe necessary or appropriate to (a) enforce the terms and conditions that govern our products and services; (b) protect our rights, privacy, safety or property, and/or that of you or others; and (c) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.
With your consent
In some jurisdictions, applicable law may require us to request your consent to use your personal data in certain contexts, such as when we use certain cookies or similar technologies or would like to send you certain marketing messages. If we request your consent to use your personal data, you have the right to withdraw your consent any time in the manner indicated when we requested the consent or by contacting us. If you have consented to receive marketing communications from our third party partners, you may withdraw your consent by contacting those partners directly.
To create anonymous data
We may create anonymous data from your personal data and other individuals whose personal data we collect. We make personal data into anonymous data by excluding information that makes the data personally identifiable to you, and use that anonymous data for our lawful business purposes.
Companies within Fiserv
We may disclose your personal data to our subsidiaries and corporate affiliates for purposes consistent with this Privacy Notice.
We may employ third party companies and individuals to administer and provide services on our behalf (such as companies that provide customer support, companies that we engage to host, manage, maintain, and develop our websites, mobile applications, and IT systems, and companies that help us process payments). These third parties may use your information only as directed by Fiserv and in a manner consistent with this Privacy Notice, and are prohibited from using or disclosing your information for any other purpose. Credit reference, fraud protection, risk management, and identity and verification agencies Fiserv shares personal data with credit reference, fraud protection, risk management, and identity verification agencies to help guard against, detect, and respond to fraud or money laundering, and/or manage our or our clients’ risk, and ensure we comply with contractual, legal, or regulatory requirements.
We may disclose your personal data to professional advisors, such as lawyers, bankers, auditors and insurers, where necessary in the course of the professional services that they render to us.
Compliance with Laws and Law Enforcement; Protection and Safety
Fiserv may disclose information about you to government or law enforcement officials (including tax authorities) or private parties as required by law, and disclose and use such information as we believe necessary or appropriate to (a) comply with applicable laws and lawful requests and legal process, such as to respond to subpoenas or requests from government authorities; (b) enforce the terms and conditions that govern our products and services; (d) protect our rights, privacy, safety or property, and/or that of you or others; and (e) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.
Fiserv may sell or transfer some or all of its business or assets, including your personal data, in connection with a business transaction (or potential business transaction) such as a merger, consolidation, acquisition, reorganization or sale of assets or in the event of bankruptcy, in which case we will make reasonable efforts to require the recipient to honor this Privacy Notice. To Other Parties with Your Permission or to Fulfill a Contract They Have With You Fiserv may transfer your personal data to any third party who is not otherwise covered by the other listed categories above where you have given us permission to do so, or with whom you have entered into a contract when we need to transfer your personal data to that party in order to fulfil that contract.
In this section, we describe the rights and choices available to all users. Users who are located in Europe may read additional information about their rights below.
You can ask us to stop sending you marketing messages at any time by contacting us or clicking on the opt-out link included in each marketing message. You may continue to receive service-related and other non-marketing messages.
Targeted online advertising
Some of the business partners that collect information about users’ activities on our websites or in our mobile applications may be members of organizations or programs that provide choices to individuals regarding the use of their browsing behavior or mobile application usage for purposes of targeted advertising.
Users may opt out of receiving targeted advertising on websites through participating members of the following organizations or programs:
- Network Advertising Initiative (USA)
- Digital Advertising Alliance (USA)
- European Interactive Digital Advertising Alliance (Europe)
- Digital Advertising Alliance of Canada (Canada)
- Australian Digital Advertising Alliance (Australia)
- Data Driven Advertising Initiative (Japan)
Users of mobile applications may opt out of receiving targeted advertising in mobile applications through participating members of the Digital Advertising Alliance by installing the AppChoices mobile application, available here, and selecting the user’s choices. In addition, your mobile device settings may provide functionality to limit our, or our partners’, ability to engage in ad tracking or targeted advertising using the Google Advertising ID or Apple ID for Advertising associated with your mobile device.
Please note that we also may work with companies that offer their own opt-out mechanisms and may not participate in the opt-out mechanisms that we linked above.
If you choose to opt-out of targeted advertisements, you will still see advertisements online, but they may not be relevant to you. Even if you do choose to opt out, not all companies that serve online behavioural advertising are included in this list, and so you may still receive some cookies and tailored advertisements from companies that are not listed.
Do Not Track Signals
Some Internet browsers may be configured to send "Do Not Track" signals to the online services that you visit. We currently do not respond to do not track signals. To find out more about "Do Not Track," please visit http://www.allaboutdnt.com.
Choosing not to provide your personal data
Where we request personal data directly from you, you do not have to provide it to us. If you decide not to provide the requested information, in some circumstances we may be unable to provide access to the Portal.
Accessing, modifying or deleting your information
In some jurisdictions, applicable law may provide a right for individuals to access, modify, or delete their personal data in some. You may contact us directly to request access to, modify or delete your information. We may not be able to provide access to, modify, or delete your information in all circumstances.
If you have a complaint about our handling of your personal data, you may contact our data protection officer using the contact information below. We request that a complaint be made in writing. Please provide details about your concern or complaint so that our data protection officer can investigate it. We will take appropriate action in response to your complaint, which may include conducting internal discussions with relevant business representatives. We may contact you for additional details or clarification about your concern or complaint. We will contact you to inform you of our response to your complaint. You also may have a right to file a complaint with a national or local regulatory agency.
Fiserv is headquartered in the United States, and it maintains offices and has service providers in other countries, such as the countries listed here. Your personal data may be transferred to the United States or other locations outside of your state, province, country or other governmental jurisdiction where we or our service providers maintain offices and where privacy laws may not be as protective as those in your jurisdiction. If we make such a transfer, we will require that the recipients of your personal data provide data security and protection in accordance with applicable law.
European users should read the important information provided here about transfer of personal data outside of Europe.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
The Portal is not directed to children or teens under the age of majority. Fiserv does not knowingly collect Personal Data at our website from persons who are not legal adults.
When you visit the Portal, you may click to websites of our affiliated companies. Those websites may have their own privacy notices that are tailored to the products and services our affiliated companies offer; in those cases, this privacy notice does not apply. If you visit the websites of our affiliated companies, please read the privacy notices for those websites.
We may also link to third-party websites, mobile applications, and other content. Fiserv is not responsible for the privacy practices of any third party, and this privacy notice does not apply to such third party’s properties. Fiserv does not guarantee, approve, or endorse any information, material, services, or products contained on or available through any linked third-party properties. Fiserv is not responsible for any content on third-party properties to which we link from the Portal. Fiserv provides links to third-party properties as a convenience and visiting or using linked third-party websites is at your own risk.
Controller and Data Protection Officer
Fiserv is made up of different legal entities. References to "Fiserv", "we", "us" or "our" in this Privacy Notice should be read to refer to the relevant company in the Fiserv group responsible for handling your data. For the purposes of the Portal, First Data Europe Limited will be the controller of your data.
We have appointed a data protection officer (“DPO”) who is responsible for overseeing questions in relation to this Privacy Notice. If you have any questions about this Privacy Notice or any privacy related queries, please contact the DPO using the details set out below:
Data Protection Officer, Fiserv
Email address: firstname.lastname@example.org
Postal address: Janus House, Endeavour Drive, Basildon, Essex, SS14 3WF, UK
Legal bases for processing
We are required to inform you of the legal bases of our processing of your personal data, which are described in the table below. If you have questions about the legal basis of how we process your personal data, please contact our DPO.
|Processing purpose||Legal basis|
||Processing is necessary to perform the contract governing our provision of the products or services or to take steps that you request prior to signing up for the Services.|
||These processing activities constitute our legitimate interests. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).|
||Processing is necessary to comply with our legal obligations.|
||Processing is based on your consent. Where we rely on your consent you have the right to withdraw it anytime in the manner indicated at the time we collect your information or by contacting us via the following link here.|
* For details of each processing purpose mentioned in the table above, see section titled “How we use your personal data”
Use for new purposes
We may use your personal data for reasons not described in this Privacy Notice where permitted by law and the reason is compatible with the purpose for which we collected it.
Automated Decisions, Credit Reference Agencies and Fraud Prevention Agencies
We sometimes make automated decisions based on your personal data (whether provided by you or collected by us from third parties). We will only do this where it is required in connection with a contract, authorized by law, or based on your explicit consent. You can contact us for more information on automated decision making. Please also see the “Your individual legal rights” section below.
How long will you use my personal data?
We will use your personal data for as long as necessary based on why we collected it and what we use it for. This may include our need to satisfy a legal, regulatory, accounting, or reporting requirement.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
In general terms, we will retain your personal data for the duration of your involvement/engagement with us and for as long as reasonably necessary afterwards. There are also certain types of information which are required to be retained for a certain period by law.
In general terms, we will retain your personal data for the duration of your involvement/engagement with us and for as long as reasonably necessary afterwards; however, we may maintain different retention periods for different products and services. There are also certain types of information which are required to be retained for a certain period by law.
You can contact us for details of the retention periods applicable to your personal data.
Your individual legal rights
Under certain circumstances, individuals in Europe have rights under data protection laws in relation to their personal data. If you are located in Europe, you may ask us to take the following actions regarding personal data that we hold:
- Access. You are entitled to ask us if we are processing your personal data and, if so, for a copy of the personal data we hold about you, as well as obtain certain other information about our processing activities.
- Correction. If any personal data we hold about you is incomplete or inaccurate, you can require us to correct it, though we may need to verify the accuracy of the new data you provide to us.
- Erasure. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law.
- Object. Where our reason for processing your personal data is legitimate interest you may object to processing as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes.
- Restriction. You may ask us to suspend our use of your personal data in the following scenarios:
- if you want us to establish the data's accuracy;
- where our use of your personal data is unlawful but you do not want us to erase it;
- where you need us to hold your data for a longer period than we usually would, because you need it to establish, exercise or defend legal claims; or
- you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
- Transfer. Where it is possible, we will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to personal data provided by you which you initially provided consent for us to use or where we used the information to perform a contract with you.
- Withdraw consent. Where our reason for processing is based on your consent, you may withdraw that consent at any time. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
- Automated decision making. You have the right not to be subject to automated decision making (e.g., profiling) that significantly affects you. The exercise of this right is not available to you in the following cases:
- The automated decision is required to enter into, or perform, a contract with you.
- We have your explicit consent to make such a decision.
- The automated decision is authorised by local law of an EU member state.
- However, in the first two cases set out above, you still have the right to obtain human intervention in respect of the decision, to express your point of view and to contest the decision.
You can submit requests to exercise these rights by contacting the Fiserv Privacy Office using the following link here. We may need to request specific information from you to help us confirm your identity and ensure you are entitled to exercise a right in respect of your personal data, for example, a merchant identification number or account number. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. There may be legal or other reasons why we cannot, or are not obliged to, fulfil a request to exercise your rights. We will use available lawful exemptions to your individual rights to the extent appropriate. If we decline your request, we will tell you why, subject to legal restrictions.
You will not have to pay a fee to exercise any of your rights relating to your personal data. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
We will respond to all legitimate requests promptly and, in any event, within any timeframes prescribed by applicable law. In general, we must respond to queries within one month from the receipt of the request, so it is important that requests are identified and submitted using the following link here as soon as possible. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated. Any transmission of your personal data will be handled in a secure manner.
You also have the right to make a complaint at any time to a supervisory authority (for more information go to https://edpb.europa.eu/about-edpb/board/members_en).
Cross-border data transfer
We transfer your personal data within the Fiserv group, including outside of Europe. Sometimes we transfer your personal data out of Europe within the Fiserv group to countries not deemed by the European Commission to provide an adequate level of protection for personal data, the transfer will be based on our Binding Corporate Rules, a copy of which can be found here. FDR LLC is the group company responsible for compliance with our Binding Corporate Rules.
When we transfer personal data outside of Europe, within the group where the Binding Corporate Rules do not apply, or to third parties in countries not deemed by the European Commission to provide an adequate level of protection for personal data, the transfer will be made pursuant to:
- A contract approved by the European Commission (sometimes called “Model Clauses” or “Standard Contractual Clauses”);
- The recipient’s Binding Corporate Rules;
- The consent of the individual to whom the personal data relates; or
- Other mechanisms or legal grounds as may be permitted under applicable European law
Please contact us if you would like to receive further information on the specific mechanism used by us when transferring your personal data out of Europe.
We reserve the right to modify this Privacy Notice at any time. We encourage you to periodically review this page for the latest information on our privacy practices. If we make material changes to this Privacy Notice, we will notify you by updating the date of this Privacy Notice and posting it on our website and in app stores where our mobile applications covered by this Privacy Notice are available for download. We may (and, where required by law, will) also provide notification of changes in another way that we believe is reasonably likely to reach you, such as via e-mail (if you have an account where we have your contact information) or another manner through our website or mobile applications.
Any modifications to this Privacy Notice will be effective upon our posting of the new terms and/or upon implementation of the new changes (or as otherwise indicated at the time of posting). In all cases, your continued use of our products or services after the posting of any modified Privacy Notice indicates your acceptance of the terms of the modified Privacy Notice.
For European privacy inquiries, you may contact our Data Protection Officer at email@example.com.
For California resident data inquiries please refer to “How to exercise your rights” below.
For all other privacy inquiries related to this Notice, please contact us at firstname.lastname@example.org.
We also maintain a Data Privacy Hotline, which is available 24 hours per day from the United States, at +1 800-368-1000. The Hotline is the most appropriate contact for an urgent concern, such as to report a suspected data breach regarding your personal data; or, if you are a merchant, data of your customers.
For questions about your credit or debit card or your purchase, please contact the financial institution that issued your card or the merchant.
We are required by the California Consumer Privacy Act of 2018 (“CCPA”) to provide to California residents an explanation of how we collect, use and share their personal Information, and of the rights and choices we offer California residents regarding our handling of the personal information.
Your California privacy rights As a California resident, you have the rights listed below. However, these rights are not absolute, and we may decline your request as permitted by the CCPA.
- Information. You can request the following information about how we have collected and used your Personal Information during the past 12 months:
- The categories of Personal Information that we have collected.
- The categories of sources from which we collected Personal Information.
- The business or commercial purpose for collecting and/or selling Personal Information.
- The categories of third parties with whom we share Personal Information.
- Whether we have disclosed your Personal Information for a business purpose, and if so, the categories of Personal Information received by each category of recipient.
- Whether we’ve sold your Personal Information; and, if so, the categories of Personal Information received by each category of recipient.
- Access. You can request a copy of the Personal Information that we maintain about you.
- Deletion. You can ask us to delete the Personal Information that we maintain about you.
- Nondiscrimination. You are entitled to exercise the rights described above free from discrimination. This means that we will not penalize you for exercising your rights by taking actions such as by denying you goods or services, increasing the price/rate of goods or services, decreasing the service quality, or suggesting that we may penalize you as described above for exercising your rights. However, the CCPA allows us to charge you a different price or provide a different service quality if that difference is reasonably related to the value of the Personal Information we are unable to use.
How to exercise your rights
You may exercise your California privacy rights to information, access and deletion as follows:
- You can request to exercise your information, access and deletion rights by:
- Identify verification. The CCPA requires us to verify the identity of the individual submitting the request before providing a substantive response to the request. A request must be provided with sufficient detail to allow us to understand, evaluate and respond. The requester must provide sufficient information to allow us to reasonably verify that the individual is the person about whom we collected information. A request may also be made on behalf of your child under 13.
- Authorized agents. California residents can empower an “authorized agent” to submit requests on their behalf. We will require the authorized agent to have a written authorization confirming that authority.
Sale of Personal Information
We do not sell your Personal Information to third parties as defined in the CCPA.
Personal information that we collect, use and share
|Categories of information we collect||Do we collect this information||Do we share this information for business purposes?|
|Protected classification characteristics||Age possible||Yes|
|Biometric information||Possible for authentication||Yes|
|Internet or network information||Yes||Yes|
|Geolocation data||Yes, if you authorise||Yes|
|Professional or employment information||Possible||Yes|