<

Effective Date: December 21, 2019
Last Updated: December 21, 2019

Paymentus Corporation (collectively referred to herein as "Paymentus", "we", "our", or "us") recognizes the importance of protecting personal data we may collect from visitors and any other individual or entity ("users", "you", or "your") who visit our web sites or otherwise provide us with personal data. This Privacy Policy applies to data collection by Paymentus and applies to your use of the website, www.paymentus.com and other Paymentus-related sites, including those we maintain for our customers ("billers"), mobile and other applications, software, communications, capabilities and services ("Services") accessible on or by any top-level Paymentus domain owned by us (each, a "Site" and collectively the "Sites"), but excluding services that state that they are offered under a different privacy policy. This Privacy Policy also applies to information we may collect from representatives of billers and from others directly at trade shows or through similar interactions.

Our Privacy Policy explains: (1) what information we collect; (2) why we collect it; (3) how we use that information; (4) how we may share it; and (5) the choices we offer, including how to access and delete information. Specifically, our Privacy Policy covers the following topics:

Please familiarize yourself with our privacy practices and let us know if you have any questions. By using the Sites, you signify your acceptance of this Privacy Policy. If you do not agree to this Privacy Policy, please do not use the Sites.

If you have any questions or comments about this Privacy Policy, please submit a request to privacy@paymentus.com.

When This Privacy Policy Applies

Our Privacy Policy applies to all of the Services offered by Paymentus and its affiliates, including some Paymentus partners, and Services offered on other sites, but excludes services that have separate privacy policies that do not incorporate this Privacy Policy.

Our Privacy Policy does not apply to services offered by other companies or individuals, including your biller, products or sites that may be displayed to you, or other sites linked from our Services. Our Privacy Policy does not cover the information practices of your biller, of other companies through which you may receive information or originate payments to or from your biller, or other companies and organizations who advertise our Services, and who may use cookies, pixel tags and other technologies to serve and offer relevant ads.

Website Conditions of Use

By accessing or using the Sites in any manner, you also agree to be bound by our Website Conditions of Use. Please read the Conditions of Use carefully. If you do not accept all of the terms and conditions contained in or incorporated by reference into the Conditions of Use, please do not use the Sites.

Information We Collect

We collect information, including personal information, to provide better services to all our users and, in the case of information we collect from individuals connected with our commercial customers or prospects, for marketing purposes. We use the term "personal information" to refer to any information that identifies or can be used to identify you. Common examples of personal information include: full name, email address, digital identity, such as a login name or handle, information about your device, and certain metadata.

The personal information we collect includes, but is not limited to, the following circumstances and data elements:

For additional information on the information we collect, please review our Privacy Notice to California Residents.

If you provide us or our service providers with any personal information relating to other individuals, you represent that you have the authority to do so and acknowledge that it will be used in accordance with this Privacy Policy. If you believe that your personal information has been provided to us improperly, or to otherwise exercise your rights relating to your personal information, please contact us by using the information set out in the "How to Contact Us" section below.

We obtain personal information from the following categories of sources:

Cookies & Similar Technologies

We and our partners use various technologies to collect and store information when you visit one of our Sites or use our mobile apps, and this may include using cookies or similar technologies to identify your browser or device. We also use these technologies to collect and store information when you interact with services from our partners, such as advertising services from our third party advertising and analytics partner Google Analytics and similar partners.

The technologies we use for this automatic data collection may include:

We use information collected from cookies and other technologies, to improve your user experience and the overall quality of our services. We may use your personal information to see which web pages you visit at our Site, how you navigate through and interact with our Site and mobile apps, which web site you visited before coming to our Site, and where you go after you leave our Site. We can then develop statistics that help us understand how our visitors use our Site and mobile apps and how to improve them. We may also use the information we obtain about you in other ways for which we provide specific notice at the time of collection.

How We Use the Information We Collect

We use your personal information in ways that are compatible with the purposes for which it was collected or authorized by you and in certain cases only as permitted by your biller, including for the following purposes:

For additional information on how we use the information we collect, please review our Privacy Notice to California Residents

Our Legal Basis for Collecting Personal Information

Whenever we collect personal information from you, we may do so on the following legal bases:

  1. Your consent to such collection and use;
  2. Out of necessity for the performance of an agreement between us and you, such as your agreement to use our Services or your request for Services;
  3. Our legitimate business interest, including but not limited to the following circumstances where collecting or using personal information is necessary for:
    • To perform services requested by your biller, our customer;
    • Intra-organization transfers for administrative purposes;
    • Product development and enhancement, where the processing enables Paymentus to enhance, modify, personalize, or otherwise improve our services and communications for the benefit of our users and customers, and to better understand how people interact with our Sites;
    • Communications and marketing, including processing data for direct marketing purposes, and to determine the effectiveness of our promotional campaigns and advertising;
    • Fraud detection and prevention;
    • Enhancement of our cybersecurity, including improving the security of our network and information systems; and
    • General business operations and diligence;

Provided that, in each circumstance, we will weigh the necessity of our processing for the purpose against your privacy and confidentiality interests, including taking into account your reasonable expectations, the impact of processing, and any safeguards which are or could be put in place. In all circumstances, we will limit such processing for our legitimate business interest to what is necessary for its purposes.

Your Failure to Provide Personal Information

Your provision of personal information is required in order to use certain parts of our services and our programs. If you fail to provide such personal information, you may not be able to access and use our Services and/or our programs, or parts of our Services and/or our programs.

Our Retention of Your Personal Information

We determine the appropriate retention period for personal information on the basis of the amount, nature and sensitivity of your personal information processed, the potential risk of harm from unauthorized use or disclosure of your personal information and whether we can achieve the purposes of the processing through other means, as well as on the basis of applicable legal requirements (such as applicable statutes of limitation).

After expiry of the applicable retention periods, your personal information will be deleted. If there is any data that we are unable, for technical reasons, to delete entirely from our systems, we will put in place appropriate measures to prevent any further use of such data.

Sharing Personal Information

Paymentus may disclose your personal information to your biller, commercial providers and trusted business partners for a business purpose, which includes verifying your identity, to enable our compliance with applicable law and payment network rules when you make a payment or register access to your accounts, to process your payment instructions, to offer you additional channels through which you may receive information about your bills or to make payments, or to test or improve our Services. When we disclose personal information for these reasons, we enter into a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except for the purposes set forth in the contract. We may also disclose personal information to governmental authorities and in connection with judicial or administrative proceedings as required or permitted by applicable law to meet legal obligations or to defend or assert our rights or the rights of others. If we establish a new related entity, are acquired by or merged with another organization, or if substantially all of our assets are transferred to another organization, personal information about our users is often a transferred business asset. In the event that Paymentus itself or substantially all of our assets are acquired, personal information about our users may be one of the transferred assets.

In the preceding twelve (12) months, we have disclosed the following categories of personal information for one or more business purposes:

We disclose your personal information for a business purpose to the following categories of third parties:

In the preceding twelve (12) months, we have not sold any personal information.

Your Rights and Choices

You may have certain rights relating to your personal information, to the extent provided by local law. We will provide you with access to your personal information as required by applicable law. If that information is wrong, we strive to give you ways to update it quickly or to delete it - unless we have to keep that information for legitimate business or legal purposes. To the extent required by applicable law, you may obtain a copy of personal information we maintain about you. To help protect your privacy and maintain security, we will take steps to verify your identity before granting you access to the information.

Third Party Links

The Sites may contain links to webpages operated by parties other than Paymentus. We do not control such websites and are not responsible for their contents or the privacy policies or other practices of such websites. These websites and services may have their own privacy policies, which the user will be subject to upon linking to the third party's website. Paymentus strongly recommends that each user review the third party's terms and policies.

International Transfer

We may, directly or indirectly through third-party entities around the world, process, store, and transfer the information you provide, including your personal information, as described in this Privacy Policy. Specifically, the information and personal information that we collect may be transferred to, and stored at, a location outside of your jurisdiction. It may also be processed by staff operating outside of your jurisdiction who work for us or for one of the organizations outlined in this Privacy Policy in connection with the activities outlined in this Privacy Policy. By submitting your information and personal information using the Sites, you agree to this transfer, storing or processing. We will take all steps necessary to ensure that your personal information is treated securely and in accordance with this Privacy Policy. We have put in place commercially reasonable technical and organizational procedures to safeguard the information and personal information we collect on the Sites.

How We Protect Personal Information

Paymentus maintains administrative, technical and physical safeguards designed to protect the user's personal information and other information against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure or use. For example, we use commercially reasonable security measures such as encryption, firewalls, and Transport Layer Security software (TLS) or hypertext transfer protocol secure (HTTPS) to protect personal information.

Paymentus collects account information for payment or credit, and Paymentus will use the information only to complete the task for which the account information was offered or as otherwise provided in this Privacy Policy.

Children

Our website is not intended for children under 16 years of age. We do not intentionally gather Personal information about visitors who are under the age of 16. If a child has provided us with personal information, a parent or guardian of that child may contact us to have the information deleted from our records. If you believe that we might have any information from a child under age 16 in the applicable jurisdiction, please contact us privacy@paymentus.com. If we learn that we have inadvertently collected the personal information of a child under 16, or equivalent minimum age depending on jurisdiction, we will take steps to delete the information as soon as possible.

"Do Not Track" Signals

Paymentus does not track its users over time and across third party websites to provide targeted advertising and therefore does not respond to Do Not Track (DNT) signals. However, some third party sites do keep track of your browsing activities when they serve you content, which enables them to tailor what they present to you. If you are visiting such sites, your browser may include controls to block and delete cookies, web beacons and similar technologies, to allow you to opt out of data collection through those technologies.

Use of Email

By providing an email address on the Paymentus Sites or Services, you agree that we may contact you in the event of a change in this Privacy Policy, to provide you with any Service related notices, or if you provided the information other than in connection with making a payment to your biller, to provide you with information about our events, invitations, or related educational information.

Changes to this Privacy Policy

Our Privacy Policy may change from time to time. We will not reduce your rights with respect to information collected under this Privacy Policy without your explicit consent. We will post any privacy policy changes on this page and, if the changes are significant, we may provide a more prominent notice (including, for certain services or programs, email notification of privacy policy changes).

How to Contact Us

If you have any specific questions about this Privacy Policy, you can contact us via email or by writing to us at the address below:

Send e-mail to: privacy@paymentus.com

Send mail to our address:

Paymentus Corporation
Attn: Privacy Policy Inquiry
13024 Ballantyne Corporate Place
Suite 400
Charlotte, NC 28277
U.S.A.

Privacy Notice to California Residents

The following information is provided to California residents to comply with the California Consumer Privacy Act of 2018 ("CCPA") and other California privacy laws and forms a part of the Paymentus Privacy Policy, the remainder of which may be viewed here. Any terms defined in the CCPA have the same meaning when used in this notice.

What We Collect

During the last twelve (12) months, we have collected the following categories of personal information from consumers depending on how a consumer uses our services.

Category Type of Identifiers We Collect
A. Identifiers. First and last name, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account number for bills you review or pay.
B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). Name, signature, Social Security number, address, telephone number, bank account number, credit card number, debit card number, medical or health insurance information.
D. Commercial information Bill payment history, utility services consumption information
F. Internet or other similar network activity. Information on a consumer's interaction with a website, application, or advertisement.

How We Use Information We Collect

We use your personal information in ways that are compatible with the purposes for which it was collected or authorized by you and in certain cases only as permitted by your biller, including for the following purposes:

Category The Purpose for Collection

Identifiers.

Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).

Commercial Information.

  • To provide you with Services;
  • To present, operate, maintain, secure, authorize access to, or personalize our Sites and Services, and to respond to and support users;
  • To improve, enhance and further develop our Sites and Services;
  • To communicate with you regarding your bills from or payment obligations to your biller;
  • To enable trusted business partners to provide you with information regarding your bill from or payment obligations to your biller and facilitate your payment of those bills or obligations;
  • To perform data analysis and testing, including analysis of Site activity;
  • To investigate possible fraud and/or attempts to harm us, our users or customers or other violations of and to enforce the Conditions of Use, our Payment Authorization Terms or this Privacy Policy, and to resolve disputes;
  • To comply with all applicable legal requirements and the rules of payment networks;
  • To inform you about Services and products available from Paymentus or your biller;
  • To offer and administer content, promotion, sweepstakes, surveys, voting polls or other Site features;
  • To otherwise fulfill the purpose for which the information was provided.

Internet or other similar network activity.

  • To authorize access to and secure our Sites and Services; including to authenticate users;
  • To provide you with Services;
  • To offer and administer content, promotion, sweepstakes, surveys, voting polls or other Site features;
  • To understand and improve the user experience of our Site and Services;
  • To support the other uses identified above.

Rights Specific to California Residents

Under the California Consumer Privacy Act, California residents have specific rights regarding their personal information. This section explains how California residents can exercise those rights and describes Californians’ rights.

If you are a California resident who chooses to exercise your rights, you can:

  1. Submit a request via email to privacy@paymentus.com, or
  2. Call (800) 420-1663 to submit your request.

Upon receiving your request, we will confirm receipt of your request by email or if you are registered in our customer portal, we may do so by a message directed to you in the portal. To help protect your privacy and maintain security, we may take steps to verify your identity before granting you access to the information. In some instances, such as a request to delete personal information, we may first separately confirm that you would like for us to in fact delete your personal information before acting on your request.

We will respond to your request within forty-five (45) days. If we require more time, we will inform you of the reason and extension period in writing. We will deliver our written response by mail or electronically, at your option.

In some cases our ability to uphold these rights for you may depend upon our obligations to process personal information for security, safety, fraud prevention reasons, compliance with regulatory or legal requirements, listed below, or because processing is necessary to deliver the services you have requested. Where this is the case, we will inform you of specific details in response to your request.

Below we further outline specific rights which California residents may have under the California Consumer Privacy Act.

  1. Right to Access Your Data. You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months. Once we receive and confirm your verifiable consumer request, we will disclose to you:
    • The categories of personal information we collected about you.
    • The categories of sources for the personal information we collected about you.
    • Our business or commercial purpose for collecting that personal information.
    • The specific pieces of personal information we collected about you.
    • The categories of third parties with whom we share that personal information.
    • The specific pieces of personal information we've disclosed for a business or commercial purpose, identifying the personal information categories that each category of recipient obtained about you.
    Any disclosures we provide will only cover the 12-month period preceding the receipt of your request. The response we provide will also explain the reasons we cannot comply with a request, if applicable.
  2. Right to Data Portability. You have the right to a "portable" copy of your personal information that you have submitted to us. Generally, this means you have a right to request that we move, copy or transmit your personal information stored on our servers / IT environment to another service provider's servers / IT environment.
  3. Right to Delete Your Data. You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.

We may deny your deletion request if retaining the information is necessary for us or our service providers to: