Logo  MPA Terms & Conditions

Merchant Processing Agreement

Terms & Conditions

Merchant Processing Agreement Terms & Conditions

Last updated: 7/31/2026

These Terms and Conditions apply to your card processing agreement. For simplicity, Luqra (“LQ”) refers to itself as “we,” “our,” “Processor,” or “us” in this document. We refer to you (i.e., the legal entity or individual representing a business named in the Application) as “you,” “your,” or “Merchant.” Other parties may also be parties to this Agreement (e.g., Member Bank, Guarantor, etc.). Terms that are capitalized, but not defined, are defined in Section 21 or in the Application.

1. Terms and Exclusivity

  1. TermThis Agreement binds you on the earlier of your execution of this Agreement, submission of your Application, or submission of a transaction. This Agreement binds us on the earlier of (i) the date we issue you a Merchant Identification Number; or (ii) the date we process your first transaction. Unless otherwise stated in the Agreement/Application, the initial term of this Agreement is 36 months (“Initial Term”). At the end of the Initial Term or any subsequent renewal term, the Agreement automatically renews for additional terms of 12 months each, unless either party gives written notice of its intent to terminate or not renew the Agreement at least 90 days before the then-current term expires, provided that if automatic renewal of this Agreement violates any Laws, the renewal term will be 30 days. For clarity, termination of this Agreement does not terminate your equipment lease, which may be subject to different term and termination provisions.
  2. ExclusivityThis Agreement is a “requirements contract.” This means you shall exclusively receive the Services and any similar services from us. Prior to exercising any right of termination or non-renewal, you agree that we shall have a right of first refusal before you enter into an agreement with a third party for the Services. Except for term length, you agree that our right includes terms and conditions that are substantially similar to those discussed with the third party.

2. Rules, Regulations, and Laws

As part of this Agreement, you agree to comply with, and to cause your employees and agents to comply with: (i) the Laws; (ii) the Operating Regulations and terminal update requirements related to optional Association programs, if applicable (and any related costs); (iii) the confidentiality and security requirements of (a) the USA Patriot Act and any related laws, rules, or regulations; and (b) the Associations and Networks, including the Payment Card Industry Data Security Standard, the Visa Cardholder Information Security Program, the Mastercard Site Data Protection Program, and any other Association or Network program or requirement. You accept any responsibility or liability (e.g., data breach liability) resulting from your decision not to participate in optional Association Programs (e.g., the Association EMV program). In the case of a conflict between this Agreement and the Operating Regulations, the Operating Regulations govern. You agree that the Processor may require changes to your website and business processes if you are found out of compliance with any of the above.

3. Acceptance of Cards

  1. Acceptance Election; Limited Acceptance. We may enable you to accept payment cards and other payment credentials bearing the marks of Visa, Mastercard, Discover, American Express, and any other Association or Other Network that we support and make available to you from time to time. Unless you and we have agreed in writing to a limited acceptance program (“Limited Acceptance”), you will accept all valid cards of each Association or Other Network that you are approved and enabled to accept under this Agreement. Any Limited Acceptance is permitted only to the extent allowed by the applicable Operating Rules and Applicable Law, and you are solely responsible for implementing and policing Limited Acceptance at the point of sale and for any related assessments, fees, fines, penalties, or costs (including costs we incur) arising from your Limited Acceptance or failure to enforce it. Our obligations are limited to those expressed in the Operating Rules. Any Limited Acceptance election applies only to U.S.-issued Cards, and merchants accepting any card bearing a Visa or Mastercard symbol must continue to accept all valid Visa and Mastercard cards issued outside the United States to the extent required by the Operating Rules. If you submit a transaction for processing that is outside your acceptance election, we may nevertheless process the transaction, and you will remain responsible for all fees, assessments, chargebacks, and other amounts associated with that transaction.
  2. If we are unable to obtain, or choose not to obtain, authorization from an Association or Other Network, we may “stand-in” for the Association or Other Network. If we stand-in, we will authorize the card transaction based on our own criteria. Our decision to stand-in does not change your obligation(s) to us.
  3. To the extent permitted by Law, you may establish a minimum sale amount as a condition for honoring credit Cards, provided that the minimum transaction amount does not differentiate between Card Organizations and/or issuers and the minimum transaction amount does not exceed $10.00 (or any higher amount established by applicable law or the Rules). You may not establish a maximum sale amount.
  4. Prohibited Disbursements: You shall not receive money from a Cardholder and subsequently prepare a credit voucher for the purpose of depositing it into the Cardholder’s account. You will not deposit any transaction for the purpose of obtaining or providing a cash advance to a Cardholder. Cash disbursement by you to a Cardholder is not permitted. You will not accept sales from Cardholders where the primary purpose of the transaction is the provision of working capital to the business and not the purchase of goods and/or services from the business.
  5. American Express Specific Requirements: If you accept American Express cards, you must comply with the American Express rules regarding card acceptance. You should review your agreement with American Express for further details on the requirements for American Express card acceptance.
  6. Authorization. Merchant agrees to properly obtain an authorization code for the total amount of the transaction and will record the authorization code on the transaction data prior to completing the transaction. Processor reserves the right to refuse to process any Card transaction presented by Merchant that does not include a proper authorization. If a Merchant completes a transaction without an authorization code, Merchant will be responsible for any Chargeback of the transaction and this Agreement may be subject to immediate termination without notice.

    Merchant agrees to submit a transaction only if the transaction is made or approved by the Cardholder who is issued the Card used for the transaction. The burden of verifying the identity of the Cardholder and the Cardholder’s authority to initiate a transaction rests solely with Merchant. You will follow any Processor and Network instructions received during the authorization process. Upon receipt of authorization, you may consummate the authorized transaction. Where authorization is obtained, you will be deemed to warrant the true identity of the customer as the Cardholder. If you receive a negative authorization response, you may not complete the sale. Transactions will be deemed invalid on Cards that are expired, regardless of whether an authorization has been obtained.

    For card-present transactions, Merchant shall examine each Card physically presented at the point of sale to determine that the Card presented is valid and has not expired. Merchant shall examine and determine that the authorized signature on any Card physically presented corresponds to the Cardholder’s signature on the transaction data. Merchant will not honor any Card if: (i) the Card has expired; (ii) the signature on the sales draft does not correspond with the signature on the Card; (iii) the account number embossed on the Card does not match the account number on the Card’s magnetic stripe (as printed in electronic form); (iv) the Card was declined as a result of an Authorization attempt. Merchant may not require a Cardholder to provide personal information, such as a home or business telephone number, a home or business address; or a driver license number as a condition for honoring a Card unless permitted by law and the Operating Rules. You may not, after receiving a negative response or decline on an authorization request, split the sale amount into multiple transactions to obtain a valid authorization for each one, so that the separate transactions total the original dollar amount of the sale.

    Authorizations are not a guarantee of acceptance or payment of the Card transaction and will not waive any provision of this Agreement or otherwise validate a fraudulent transaction or a transaction involving the use of an expired Card. Obtaining an authorization will not assure payment to you for a Card transaction. The fact that an authorization is obtained by you will not affect Processor’s or Member Bank’s right thereafter to revoke the authorization of a Card transaction or to charge back the transaction to you. In no event will the fact that an authorization is obtained by you be deemed Processor’s or Member Bank’s representation or warranty, either express or implied, that the particular Card transaction is in fact a valid, authorized, or undisputed transaction entered into by the Cardholder.

4. Our Responsibilities

  1. We will provide the Services in accordance with our then-current systems and standards. Nothing requires us to provide you with any special programming; any system, program, or procedure implementation; or any special hardware or software.
  2. We will provide reports online for each fiscal day’s activity by 10:00 AM ET the next calendar day. Such reports will include an accounting for each currency with supporting details of transaction activity, daily proceeds, reserves, and funds transfers for transaction settlement. Reports will be available for download on the online reporting tool for a period of 14 months from the date of issue. Reports may be upgraded, enhanced, and/or modified by us at any time.
  3. We will initiate payment to you for the amount of each accepted Card transaction only after we receive the funds. We have no obligation to deliver payment for any Card transactions that violate the terms of this Agreement or the Operating Regulations, regardless of when we become aware of any such violation, and the proceeds from any such transactions, including any proceeds held in the Reserve Account, are not amounts due to you or held for your benefit.
  4. We have the right to honor and rely on the request(s) or instruction(s) of any person we reasonably believe to be your representative. In the event we receive returned mail intended for you, we may, but are not required to, procure a replacement address according to our standard operating procedures.
  5. We are only responsible for processing credits and adjustments for Card transactions that we originally processed. You authorize us to audit all Card transactions and deposits. We have the right to withhold amounts from you if we discover inaccuracies as otherwise set forth herein.
  6. We may report information about your account, late payments, missed payments, or defaults to credit bureaus.
  7. We may take steps to confirm your compliance with the Laws and Operating Regulations. We may suspend or cease providing any Services to you in response to a Member Bank, Network, or Association request. We will use reasonable efforts to notify you if we suspend or cease any Services.
  8. We are responsible for the security of Cardholder data we store or transmit on your behalf only while it is in our possession and control.

5. Your Responsibilities

  1. We have the right to charge your Designated Account (as defined in Section 7) without notice, or to require payment from you in any appropriate situation, for the amount of any Card transactions. This right includes Card transactions: (i) where merchandise is returned; (ii) where there is no valid authorization response; (iii) where the Cardholder has not given authority (e.g., improperly drawn, accepted, or endorsed transactions); (iv) where the Card transaction record is illegible; (v) where the Cardholder disputes the sale, quality, or delivery of merchandise or performance or quality of services; (vi) where the Card transaction was drawn by, or depository credit given to, you in a way that breaches the Agreement or violates the Laws or Operating Regulations; (vii) where we have not received and retained payment for the Card transaction (even if we have already paid you for the transaction); (viii) where it is alleged that you have failed to comply with the Operating Regulations or the Laws; (ix) where an Association or Other Network action (e.g., a Chargeback or compliance case) is pending or has been resolved against you; (x) where we have incurred claims, damages, or losses from any source, including Card issuers; or (xi) where the extension of credit for a Card transaction violated the Laws or Operating Regulations. Additionally, you remain fully liable to us for any transaction returned to us for any reason, including but not limited to Chargebacks or reversals for debit Card transactions. You agree to review all Chargeback- and reversal-related notices and reports (in any format). Your failure to respond to a Chargeback or reversal within the applicable deadline may forfeit your Chargeback rights. We have no duty to assist you in defending a non-compliance allegation related to a Chargeback.
  2. You represent that any information you have supplied to us is true and accurate and that the name and tax identification number (“TIN”) on the Application matches the name and TIN that you use to file your tax returns. You agree to update your information with us when it changes. We may need to share your TIN, entity name, processing volume, principal’s social security number, or other information with governmental entities. You agree to cooperate with our requests for information for any reason. We may be required to withhold processing funds or to forward processing funds to the IRS if you supply incorrect information, or the Laws or government agency so requires. You expressly release us from any liability in connection with our withholding of funds or submission of information to a government agency, even if incorrect. You are responsible for any fines or penalties assessed against you or us.
  3. You shall provide us a complete and accurate list of all websites and web addresses (“URLs”) that you use to market or promote your goods. The list of URLs shall be provided for an initial compliance review in connection with your Application and upon our request at any time thereafter. It is your responsibility to update the list of URLs on an ongoing basis and to notify us of any new URLs for a compliance review prior to processing any Card transactions through such URLs. You acknowledge and agree to make any changes to the content on such URLs that we deem necessary or appropriate in our sole discretion, including for purposes of compliance with Operating Rules or Laws. Notwithstanding the foregoing, we shall have no liability whatsoever to you or any third party regarding your URLs. You shall not submit any Card transaction flowing from a URL that has not been subject to such compliance review.
  4. You shall not sell, purchase, provide, share, or exchange Cardholder name, address, account number, or other information to any third party (including your Agent) other than us, the Associations, or the Networks, and then only for the purpose of completing a Card transaction.
  5. You agree to balance and reconcile the Designated Account and the Reserve Account (as defined in Section 11) each day. You shall immediately notify us of any missing or improperly deposited funds. Additionally, you agree to review our (or our agents’) reports (including those made available online), notices, and invoices. You agree to accept any report, notice, invoice, Service deficiency, or billing or payment error if you fail to reject or dispute it in writing within 30 days of the date we made it available to you. We may make our reports, notices, and invoices available to you in accordance with our standard processes, which are subject to change. For 60 days following our receipt of your written notice of an error or deficiency, you agree to refrain from making any loss or expense claims against us so that we have time to investigate the situation. If you notify us that a Card transaction batch has not processed, we may, at our option, attempt to re-present the missing Card batches dated during the 90-day period preceding the date we received your notice. We have no obligation to correct any errors that flow from your failure to comply with the duties and obligations in this paragraph.
  6. You agree to provide us with audited annual financial statements for your business, using generally accepted accounting principles, at any time upon request. Additionally, you agree to provide any other financial information within 75 days of a request by us.

  7. You shall timely assist us in complying with all Laws and Operating Regulations related to the Services. This obligates you to execute and deliver all instruments, including documents, we deem necessary for you to meet your obligations under the Agreement. Further, you agree to allow our auditors (third-party or internal), and the auditors of any Association or Other Network, to review the documents, records, procedures, systems, controls, equipment, and physical assets related to your transactions upon reasonable notice at any time. You also agree to assist our auditors as necessary. If an Association, Member Bank, or government agency requires a third-party audit, or if the Operating Regulations or Laws require a third-party audit, we may retain a third party to perform the audit or require you to immediately retain a specific third-party auditor and provide us with a final audit report. You agree to pay our audit costs or the audit costs of Member Bank, an Association, or Other Network.
  8. In the case of a delayed merchandise delivery, you agree to deliver the Card transaction record to us within two (2) business days of the merchandise delivery. You agree to electronically deliver all other Card transactions and credit records to us in a suitable format within two (2) business days of the transaction (unless the Associations or Networks require the records earlier). You also agree to deliver Card transactions and credit records to us at least once every business day. Your delivery constitutes an endorsement of each recorded transaction. You authorize us or our representative to place your endorsement on any Card transaction at any time. We have the right to refuse to acquire any Card transaction. You waive notice of dispute related to any individual Card transaction.
  9. You shall not store Cardholder data, including Track 2 data, in violation of the Laws or the Operating Regulations. Further, you shall not retain or store magnetic stripe data following the authorization of a Card transaction.
  10. You are solely responsible for the quality, accuracy, and adequacy of all transactions and information you supply. Accordingly, you shall implement and maintain adequate audit controls for monitoring the quality and delivery of data. When submitting Card transaction, settlement, and other data and information to us, you agree to follow our communications processes and document formats. You agree to only transmit information and data to us with a secure system.
  11. You may use a third-party agent (“Agent”) to perform some of your obligations under this Agreement, subject to our approval. Agents include your software providers and equipment providers. You shall cause your Agent to complete any Association-required steps or certifications (e.g., registrations, PCI DSS, PA-DSS, audits, etc.). You shall ensure that your Agent complies with all applicable requirements of this Agreement. You expressly assume all responsibility for the acts or omissions of your Agent as if they were your acts or omissions. If your Agent qualifies as a service provider under applicable Operating Regulations, you agree, at your expense, to cause the Agent to cooperate with us in our due diligence requests and in performing any steps required for registration and certification. You are responsible for conducting your own due diligence on your Agents, including the fitness of their services for a particular purpose and for determining the compliance of their services with the Operating Regulations and the Laws. You expressly assume all liability for the acts and/or omissions of your Agent even if we introduce or recommend the Agent, or resell the Agent’s services.
  12. You agree that it is important to notify us about changes in your business. Because of this, you agree to provide us 30 days prior written notice of your intent: (i) to change business form or entity type; (ii) to sell stock or assets to another entity; or (iii) to make changes that would affect information on your Application, including but not limited to a change in the types of products or services that you sell or the types of business activities in which you are engaged. Additionally, you shall notify us within three days of any judgment, writ, warrant of attachment, execution, or levy against any substantial part (25% or more) of your assets. Should you change or add locations, you agree to follow our standards and procedures. Unless we agree otherwise, you agree that you will only present Card transactions to us that correspond to the activities and volumes described on your Application. Accordingly, we must pre-approve in writing increases in Card transaction volume over the amount stated on your Application. Changes in monthly volume, the stated average ticket size, or any other information on your Application entitle us to increase fees, delay or withhold settlement, or terminate this Agreement. Your failure to notify us of changes under this Section subjects you to liability for any losses or expenses we incur.
  13. Excessive: Notwithstanding anything in this agreement to the contrary, your presentation to us or Member Bank of Excessive Activity will be a breach of this Agreement and may result in an Excessive Activity Fee as set forth in Exhibit C, as may be updated by Processor from time to time, and/or immediate termination of this Agreement, in our sole discretion. “Excessive Activity” means, during any monthly period for any one of Merchant’s terminal identification numbers or merchant identification numbers: (i) the dollar amount or number of chargebacks, fraud cases, and retrieval requests exceeds 1% of the average monthly dollar amount or number of Card transactions; (ii) sales activity that exceeds by 25% or more the dollar volume indicated on the Merchant Application; or (iii) the dollar amount of returns equals 3% of the average monthly dollar amount of Card transactions. You authorize, upon the occurrence of Excessive Activity, us or Member Bank to take any action deemed necessary including, but not limited to, suspension or termination of processing privileges or creation or maintenance of a Reserve Account in accordance with this Agreement. The “Excessive Activity Fee” shall be equal to up to 1% of the amount constituting Excessive Activity.
  14. Inactivity: Unless you are a seasonal merchant, failing to process any sales transactions for at least two (2) consecutive calendar months is considered an Event of Default and subject to the provisions of Section 9 of this Agreement.
  15. Virtual Private Network (“VPN”)/Secure Socket Layer (“SSL”): Our standard VPN and SSL services establish an internet connection between you and us for processing your transactions. You are responsible for: (i) ensuring that your communication equipment is compatible with our VPN or SSL; (ii) ensuring that each terminal with a connection to the VPN or SSL has an active personal firewall; and (iii) ensuring a secure key exchange and key management process (including a process for key revocation when your personnel leave). Our VPN or SSL communication interface relies on the internet. You agree that the internet is not always reliable, and that internet problems and issues may interfere with our ability to process your transactions. Any service levels that appear in other parts of the Agreement do not apply to the VPN or SSL connection or to transactions transmitted using the VPN or SSL connection. We provide VPN and SSL services in accordance with our own standards, which are subject to change without notice. You agree to comply with any VPN and SSL standards we or the Associations or Other Networks establish.
  16. Optional Services:We may offer you products and services through one or more third parties (“Optional Services”). You agree that, as available, the applicable third-party provider (“Provider”) solely supplies and/or supports all Optional Services. We are not a party to your contracts with Providers. You are responsible for conducting your own due diligence on any Provider that you use, including the fitness of its services for a particular purpose and for determining the compliance of its services with the Operating Regulations and the Laws, even if we resell the Provider’s services. You bear all of the risks associated with using an Optional Service. Although not an exhaustive list, we are not liable for: (i) exercising control over Provider; (ii) errors related to establishing and maintaining account relationships with Providers; or (iii) ensuring service levels with respect to the Optional Service(s). Our decision to offer any Optional Service shall not limit your duty to: (i) ensure that all account numbers are correct; (ii) notify Providers of changes to your ACH, address, and account information; (iii) pay all fees, fines, damages, losses, or expenses arising in connection with your possession or use of an Optional Service; (iv) perform your own due diligence before using an Optional Service; and/or (v) perform any other proper act related to your use of the Optional Service. You agree to indemnify and hold us harmless for any damage, loss, claim, or liability arising from your possession and/or use of any Optional Service. Each Provider has the right to require you to enter into a separate agreement with it. Whether you and Provider enter into a separate agreement, you agree that: (i) your rights and duties regarding the use of an Optional Service are neither assignable nor delegable without Provider’s prior written consent; (ii) you acquire no property right, intellectual property right, claim, or interest in any of Provider’s systems, equipment, software, processes, programs, or data; and (iii) you shall protect the confidentiality of Provider’s software and documentation.
  17. You agree to pay us all Provider-imposed fees and assessments in connection with your use of the Optional Service(s). Your obligation to pay us shall continue until: (i) you have notified Provider(s) of your intent to cancel the Optional Service(s); (ii) you have provided us with notice that (a) you have notified Provider of your intent to terminate, (b) you have returned all equipment and software to Provider, and (c) you have ceased receiving all Optional Services; and (iii) Provider no longer assesses us for your receipt of the Optional Services or for possession of the equipment. You waive all rights to contest, challenge, or withhold payment for any fees we assess for Optional Services until you have satisfied the conditions in the preceding sentence.
  18. You authorize us to contact your customers or their Card issuing bank(s) to find out information about any Card transaction. You shall not contact a Discover Cardholder unless authorized to do so by the Operating Regulations or required by Law.
  19. Bankruptcy: You agree to execute and deliver to us any documents we request to perfect and confirm the lien, security interest, and setoff rights in this Agreement. You shall immediately notify us of any bankruptcy, receivership, insolvency, or similar action or proceeding initiated by or against you or any of your principals. Further, you shall include us on the list of creditors filed with the Bankruptcy Court, even if no claim exists at the time of filing. This is an executory contract to make a loan or extend other debt financing or financial accommodations to or for your benefit and, as such, cannot be assumed or assigned in the event of your bankruptcy. This is a contract of recoupment and we are not required to file a motion for relief from the automatic stay to realize on any of the Secured Assets. Nevertheless, you agree not to contest a motion for relief from the automatic stay. You must adequately fund the Reserve Account to provide us with adequate protection under Bankruptcy Code § 362. We have the right to consume and offset against the Reserve Account to cover your obligations under this Agreement, regardless of whether they relate to transactions created before or after your bankruptcy filing. Because this Agreement contemplates the extension of credit for your benefit, you acknowledge that you cannot assign the contract in the event of a bankruptcy. We may immediately terminate the Agreement if you fail to comply with any part of this Section.
  20. Wireless Service Acknowledgement: We are not responsible for verifying your wireless service coverage, for losses in coverage, or for your failure to maintain coverage. By selecting wireless service, you acknowledge that wireless coverage is not guaranteed and that we have no control over the wireless service providers or the decisions they make. Additionally, you acknowledge that if wireless service is lost in your area, the equipment will not operate with another wireless carrier. We are not liable if wireless coverage is lost in a specific area and the equipment can no longer be used as a wireless terminal.
  21. Virtual Terminal Processor Services and Fees: Our Virtual Terminal Processor Service (the “Virtual Terminal Service(s)”) is an additional service (subject to separate fees and charges). It allows you to effectuate Card transactions within the merchant portal application in accordance with your user IDs. You represent and warrant that you have implemented and will maintain secure systems for using the VT Services and transmitting information to us. You are responsible for any authorized or unauthorized transactions initiated using your user IDs. You assume all liability for (i) acts or omissions arising out of your use of the VT Services; and (ii) risks associated with using software with internet connectivity.
  22. Equipment: If you enter into a lease or rental agreement for the use of credit card processing equipment, you understand that such agreement is separate and apart from this Agreement and is subject to the terms and conditions of the lease or rental agreement. Neither we nor Member Bank is a party to any such lease and neither is affiliated with the third-party institutions. Such leases are typically non-cancelable 48-month leases. Termination of your Agreement with us does NOT automatically terminate your equipment lease, it only terminates your processing agreement with us. You acknowledge that you have selected the equipment set forth on the Merchant Application based upon your own independent evaluation and you are not relying upon any warranty or representation of any third party, including but not limited to the representations of a sales representative, regarding the equipment. Processor is not responsible for and is not able to provide customer service for equipment, such as POS devices, installed by and/or operated by any third party. Merchant should contact the third party for service of this equipment. Merchant shall not allow any third party to install, remove, or modify any terminal equipment or software application of ours or Member Bank without the express written consent of us or Member Bank.
  23. Responsibility for Transactions: You are responsible for ensuring that the Cardholder understands that Merchant is responsible for the transaction, including goods or services included as part of the transaction, and for related customer service, dispute resolution, and performance of the terms and conditions of the transaction. Merchant must prominently and unequivocally inform the Cardholder of the identity of the Merchant and all actions so that the Cardholder readily can distinguish the Merchant from any other entity such as a supplier of goods or services.
  24. Return Policy: You will properly disclose to the Cardholder, at the time of the transaction and in accordance with the Rules, any limitation you have on accepting returned merchandise. Merchant agrees to maintain a written refund policy that complies with the Operating Regulations and Applicable Law and to disclose such policy to Processor and all customers. Merchant will submit any changes to its refund policy to Processor in writing at least fifteen (15) days before the change and will not implement any change to which Processor reasonably objects. If Merchant operates a website through which sales are processed, Merchant must include its refund policy on the website in accordance with the Operating Regulations and Applicable Law. Merchant will make a refund or adjustment in cash only to the extent permitted by Applicable Law and the Operating Regulations. Merchant will deliver to Processor all information reflecting such refund or adjustment within three (3) days of the refund or adjustment. The amount of any refund must not exceed the amount of the original transaction except for any amount which Merchant agrees to reimburse the Customer for return postage. Merchant will not accept any payment from a customer as consideration for issuing a refund If you accept American Express cards, your refund policy must be at least as favorable for American Express as your refund policy for other payment methods.
  25. Age Restricted Products: You may not offer, market, or sell any age-restricted products or services (including alcoholic beverages, tobacco products, weapons, or any other age-restricted products or services) in connection with the Services under this Agreement unless you have obtained Luqra’s prior written approval, which must expressly authorize such activities. Any material change to the nature, scope, or manner of such sales (including changes to your website or product catalog) likewise requires Luqra’s prior written approval. If you are engaged in the sale of age-restricted products, you must comply fully with all local, state, and federal laws and Operating Regulations governing the marketing, sale, and distribution of age-related products.
  26. Fraud and Factoring: You agree that, except as otherwise specified herein or permitted by Processor, you will use the services provided by Processor solely for your own internal and proper business purposes. You will not resell, directly or indirectly, any portion of the services to any third party. Transactions deposited must directly result from Cardholder transactions at your merchant locations. You will not deposit transactions resulting from any Card transaction between a Cardholder and another entity (except for Payment Service Providers (PSPs) depositing transactions from a transaction between a Cardholder and a Sponsored Merchant of the PSP). You will not present for processing or credit any transaction not originated directly between you and a Cardholder, or any transaction you know or should know is fraudulent or unauthorized.

6. Risk Monitoring and Audit

  1. Processor may monitor Merchant’s transactions for risk management purposes. If Processor identifies unusual or suspicious activity (including, without limitation, unauthorized transactions, excessive Chargebacks or excessive activity, suspected or actual fraud, and/or breach or default), Processor is authorized to take protective actions including closing terminals, blocking transactions, holding funds (including, without limitation, charging additional discount rates and/or fees as a reserve or additional reserve), and investigating these matters. Merchant agrees to hold Processor and its affiliates harmless from and against any and all claims related to risk monitoring.
  2. Merchant authorizes Processor to audit Merchant’s records, systems, processes or procedures to confirm compliance with this Agreement, as amended from time to time. Merchant shall provide financial statements and other information concerning Merchant (including its affiliates), Merchant’s business and Merchant’s compliance with the terms and provisions of this Agreement as Processor may reasonably request. In addition, Merchant agrees to cooperate in any audit, examination, or investigation as may be required by Processor, Network, Association, or other payment system, or a governmental authority; and upon request and reasonable prior notice, permit Processor, Network, Association, or other payment system, or governmental authority to conduct an on-site inspection of Merchant’s premises and examine Merchant’s books, records, practices, and systems, to the extent that each pertains to compliance with this Agreement. Any audit that is required by Applicable Law or Operating Rules will be at Merchant’s sole expense. Processor and any other applicable entities shall have the right to retain a third party to perform any audit.
  3. Merchant agrees to implement any changes identified pursuant to an audit necessary to remediate or prevent any violation of Applicable Law or the Rules. If Processor, in its discretion, determines that there is a need for an audit regarding a potential violation of Applicable Law or the Rules, Processor may withhold payment of amounts owed to Merchant without penalty pending completion of the audit. If it is determined that there has been a violation of Applicable Law or the Rules relating to this Agreement, Processor may withhold payment of amounts owed to Merchant for a reasonable amount of time in an amount equal to the costs, fees, and expenses incurred by Processor in investigating and resolving the same and for any damages incurred by Processor. Merchant shall provide Processor with written notice not more than five (5) days after Merchant receives any subpoena, civil investigative demand, or similar request for information from a federal, state, or local government, agency, or entity relating to the Processor Services or this Agreement.

7. Fees and Other Services

  1. You agree to pay fees, cost escalations, assessments, tariffs, penalties, and fines we incur caused by your use of the Services, claims, or other items under this Agreement or the Operating Regulations. We will periodically (daily, monthly, etc.) calculate your fees and charges and debit the bank or deposit account(s) that you designate (“Designated Account(s)”) to collect those amounts. We have the right to determine and change the periodic basis (daily, monthly, etc.) in the previous sentence in our sole discretion, without notice. We have the right to round, assess, and calculate interchange and other fees and amounts in accordance with our standard operating procedures. We also have the right to assess some or all of the fees and charges via a separate or combined Services invoice(s). We will charge you for any fines, fees, penalties, loss allocations, assessments, registration expenses, certification expenses, telecommunication expenses, sponsorship fees, and other amounts assessed by Member Bank and/or third parties or incurred as a result of your actions, omissions, or use of the Services, or those we incurred on your behalf under the Operating Regulations and the Laws. We will provide 30 days’ notice prior to a material change in fees or fee calculation that increases the fees charged to you.
  2. Per Item fees are fees charged on each authorization, Card draft, credit draft, or other transaction type, regardless of the stated total (“Per Item Fee(s)”). We may charge a Per Item Fee for any transaction activity.
  3. Visa, Mastercard, and Discover Interchange fees, assessments, and other amounts will be either (i) assessed to you separate from and in addition to the Discount Rate, Per Item Fee, and other fees listed in the Application; or (ii) included in the Discount Rate and/or Per Item Fee listed in the Application. For American Express Card transactions, we will assess interchange fees, assessments, and other fees in addition to the Authorization Per Item Fee and other fees described in the Application. For American Express Card transactions under Tiered Transaction Pricing, interchange fees and other amounts will be included in the Discount Rate and/or Per Item Fee listed in the Application. For Debit Card transactions under Tiered Transaction Pricing, we will assess interchange fees, sponsorship fees, switch fees, and gateway fees as pass-through, and other amounts will be included in the Discount Rate and/or Per Item Fee listed in the Application. Certain fees are available upon request or through the Associations. You are responsible for conducting your own inquiry into the nature and type of applicable fees. The Discount Rate, Per Item Fee, and other fees may be based, in whole or in part, on interchange rates, assessments, and other fees that the Associations and Other Networks periodically change.
  4. You acknowledge that in order to receive the best Discount Fee and Per Item Fee on a particular Card transaction, the transaction must first “qualify” and exactly meet certain criteria. Several factors can prevent a Card transaction from qualifying, including that it: (i) was hand-entered (i.e., the encoded card information was not read by a POS device); (ii) was voice-authorized; (iii) was not authorized; (iv) was not transmitted for processing within 24 hours; (v) was a Consumer or Commercial Reward transaction, a Visa Signature transaction, or a Mastercard World Elite Card transaction; (vi) was deemed a “Non-Qualifying” transaction by the Operating Regulations (e.g., certain foreign transactions or transactions from business, commercial, purchasing, or government Cards); (vii) was difficult to capture; (viii) was difficult to authorize; (ix) was submitted incorrectly; or (x) was not eligible for the lowest electronic interchange fee for any other reason. Additionally, you might not qualify for the best Per Item Fee or Discount Rate if your average ticket differs from what we used to calculate the Per Item Fee and/or Discount Rate; if you submit more than 5% of your monthly Card drafts without electronic transmission; or if your terminal, software, or communications lines fail to function properly. The Associations change the transaction qualification criteria from time to time. For certain non-qualifying transactions, we assess a surcharge of a certain percent of the transaction amount. In the event that your Card transactions under Tiered Transaction Pricing do not qualify or only partially qualify for the qualified discount rate quoted on the Merchant Price Schedule and/or the Operating Regulations, you agree to pay the Mid-Qualified Discount Rate and/or Per Item Fee, or Non-Qualified Discount Rate and/or Per Item Fee set forth on the Application. We do not guarantee that your transactions will qualify for any given rate, and we disclaim all responsibility and liability for a transaction’s failure to so qualify. In addition, Card transactions that do not meet the necessary criteria for payment are subject to complete denial and/or Chargeback.
  5. You shall pay all taxes imposed in connection with the Services. If we pay taxes for you, we can immediately debit your Designated Account or demand payment from you.
  6. Your use of any service not listed on the Application or provided at the commencement of the Agreement obligates you to pay any accompanying fees, charges, and related expenses. If you receive these Services, you will be deemed to have consented to the fees, charges, and expenses. We have no obligation to enhance or customize Services or additional services, but we may choose to do so for a separate fee. You shall take all necessary steps to ensure that you can receive the Services, at your own cost. This includes procuring equipment and software and taking other steps as we direct.
  7. We reserve the right to charge you a reasonable fee if we reasonably believe you are not fully compliant with the Operating Regulations, the Payment Card Industry (“PCI”) Data Security Standard (“PCI DSS”) and Payment Application Data Security Standard (“PA-DSS”), or any Laws, or if you fail to prove compliance upon our request. This fee will be in addition to any other amounts payable under the Agreement.
  8. After your initial conversion to us, you agree to pay all direct and indirect costs (including those we, our affiliates, or our agents incur) related to any conversion to or from us as applicable, and/or relating to any programming effort affecting the Services.
  9. If we advance funds to you or delay your obligation to pay funds, we reserve the right to assess you a cost of funds in the manner and amount of our determination. After we approve your Application, we will begin assessing any applicable monthly recurring charges. This Agreement subjects you to an Annual or Semiannual Fee and a Monthly Minimum Fee, unless otherwise noted on the Application. In the event this Agreement expires or terminates for any reason, the Annual or Semiannual Fee, as applicable, will not be prorated or refunded. If applicable, we may assess the ACH Fee listed on the Application for administrative services.
  10. If Processor reasonably determines that Merchant’s activity is trending toward, approaching, or exceeding any VAMP metric or threshold, as defined by Visa, or any Processor VAMP Threshold, Merchant agrees to be automatically enrolled in Processor’s VAMP and TC40 reporting module and agrees to pay the Reporting Module Fee set out in the Processor’s VAMP Threshold Fee Schedule, as set forth in Exhibit C and as may be updated by Processor from time to time.
  11. Chargebacks: Merchant has full liability and responsibility for all Chargebacks. Failure to comply with this Agreement or Operating Rules will reduce Processor or Member Bank’s ability to reverse chargebacks and increase the likelihood of your receiving a chargeback.

    You may be subject to a chargeback on sales for a minimum period of 180 days from the date the sale was entered into the Association’s processing system. Processor may hold funds from your account to cover any chargebacks for the later of: (i) 270 days after the termination of this Agreement; (ii) 180 days after the last Card processing activity under this Agreement; or (iii) the conclusion of any pending criminal, civil, administrative, or regulatory investigation or litigation.

    Processor or Member Bank will mail or otherwise deliver all chargeback documentation to the address provided by you. You agree to respond promptly to all chargebacks. If Processor or Member Bank elects, at its discretion, to take action on chargebacks after the Association time limits have expired, such action shall be done at an additional cost. You will not redeposit sales that have been previously charged back and not represented. This restriction applies whether or not the Cardholder consents to such activity. If you receive a chargeback for an international Cardholder, you are responsible for any currency conversion differences in the dollar amount.

    You will be charged the fee indicated on the Merchant Application for each chargeback and as indicted on the Excessive Activity Fee Schedule (as set forth in Exhibit C) for each chargeback when chargeback activity exceeds excessive activity thresholds. To the extent that Processor has paid or may pay a Chargeback or return, Merchant will be obligated to reimburse Processor for any sums Processor has paid. Each chargeback is immediately due and payable by Merchant. Without limiting Processor’s other remedies or Processor’s security interest described in this Agreement. Processor may deduct, debit, and withhold the amount of a chargeback or anticipated chargeback from settlement amounts, the Reserve Account, or any amounts owed to Merchant by Processor under this Agreement. Merchant must immediately pay any fines or fees imposed by a Network, Association, or Processor relating to chargebacks.

    We may, in our sole discretion, enroll Merchant in chargeback and dispute management programs offered by Verifi and/or Ethoca to help minimize disputes and consumer complaints. Unless otherwise agreed in writing, Merchant will be charged the then-current fee of $30.00 per alert (or any lower fee we make available).

8. VAMP Monitoring and Remediation

  1. Program Compliance: Merchant must operate the Services to keep VAMP Metrics below the then-current (i) Processor VAMP Thresholds and (ii) Visa thresholds applicable to Merchant’s region and activity.
  2. Controls: Without limiting the foregoing, Merchant shall implement and maintain industry-standard controls designed to prevent Merchant from exceeding enumeration thresholds.
  3. Early Warning: Upon Processor’s notice that Merchant’s VAMP Metrics are trending toward or exceeding excessive thresholds, including Processor VAMP Thresholds, Merchant shall, within 5 Business Days, deliver and implement a written remediation plan acceptable to Processor.
  4. Remediation: Without limiting any other rights in the Agreement, if Processor reasonably determines that Merchant’s activity is trending toward, approaching, or exceeding any VAMP Metric or threshold, including Processor VAMP Thresholds, Processor may require immediate implementation of specified controls; Merchant shall implement them at its expense and within the timelines set by Processor. Processor may audit Merchant’s risk controls and remediation measures on reasonable notice. Merchant shall cooperate with Processor and provide such reasonably requested materials, data, logs, and artifacts and provide Processor with reasonable access to validate remediation and related controls.
  5. Other Remedies. In addition to any other remedies provided under this Agreement, Processor may, in its sole discretion, (i) establish or increase a Reserve, (ii) delay, or suspend funding, and/or (iii) reduce settlement frequency if Processor determines VAMP Metrics (including Processor VAMP Thresholds) or related conditions (including enumeration) present heightened risk or may trigger Visa identification at the merchant or acquirer-portfolio level. If Merchant fails to maintain Metrics below thresholds, including Processor VAMP Thresholds, or fails to complete remediation on time, Processor may suspend Services or terminate this Agreement for cause on written notice.
  6. Pass-Through and Processor Costs: Merchant shall reimburse and indemnify Processor for all assessments, fines, penalties, fees, and costs arising out of Merchant’s VAMP identification or VAMP-related remediation. In addition, Merchant shall pay Processor’s VAMP-related costs and fees (including administrative, monitoring, remediation, and operational costs) in accordance with Processor’s VAMP Threshold Fee Schedule, as set forth in Exhibit C and as may be updated by Processor from time to time.

9. Termination or Suspension of Services

  1. Default Event: You are in default under this Agreement (“Event of Default”) if: (i) we believe there has been a material or potentially material deterioration of your financial condition; (ii) you become subject to any voluntary or involuntary bankruptcy, insolvency, reorganization, or liquidation proceeding, a receiver is appointed for you, or you make an assignment for the benefit of creditors, or admit your inability to pay your debts as they become due; (iii) you cease doing business as a going concern, or there is a Change in Control; (iv) you are in breach of any of the terms of the Agreement; (v) we reasonably believe fraud may be occurring including, without limitation, splitting tickets or laundering tickets; (vi) your name or your principals’ names are listed on the MATCH (Membership Alert to Control High Risk Merchants) System, Discover Merchant Control, or other security or credit alert systems, or you are identified under an Association risk monitoring program; (vii) we determine that your Card transactions or the circumstances surrounding your Card transactions have become irregular or increase our exposure to Chargebacks, reputational, or other security risks; (viii) we receive instructions from an Association or Other Network to close your account; (ix) you become subject to any criminal or civil action, suit, or proceeding or to any government or regulatory investigation or enforcement action; (x) circumstances exist that could cause harm or loss of goodwill to the Associations or Other Networks; (xi) you no longer meet the eligibility requirements of an Association or Network; (xii) you present Excessive Activity for processing; (xiii) you experience returns greater than 3% in a month or Chargebacks greater than 0.50% in a month; (xiv) Processor reasonably determines that your VAMP Ratio, as defined by Visa, meets or exceeds 0.50%, the Processor VAMP Ratio Threshold, or then-current Visa excessive VAMP thresholds (including enumeration thresholds); (xv) you cease doing the kind of business described in the Application; (xvi) you fail to process any sales transactions for at least two (2) consecutive calendar months and are not a seasonal merchant; (xvii) you fail to pay any amount owed under this Agreement to us when due; (xviii) we believe that you have violated or are likely to violate the Operating Regulations or the Laws; (xix) you engage in, or are suspected to have engaged in any of the following acts: (a) illegal business activities; (b) collusive fraudulent transactions with Cardholders; (c) laundering or aggregating illegal and/or brand damaging transactions; (d) establishing your account with us through identity theft; or (e) any other fraudulent act (each such act, an “Improper Transaction”); (xx) you assign this Agreement without our prior consent; or (xxi) you solicit or accept mail orders or telephone orders or any transaction in which the Cardholder and Card are not present without prior written authorization from us. We shall determine the existence of an Event of Default and our determination is conclusive unless you contest it in writing within 90 days following our determination. Upon the occurrence of an Event of Default, we may exercise any right or remedy in this Agreement with or without notice, or may decide to pursue no remedy at all in our sole discretion. Our remedies for an Event of Default include: (i) terminating the Agreement; (ii) suspending or ceasing to provide the Services; (iii) collecting the Early Termination Fee, if applicable; (iv) diverting all Card transaction proceeds to a Reserve Account; (v) collecting any amounts you owe us by means of setoff, recoupment, or any other legal means; (vi) recovering fees and costs, including attorneys’ fees associated with the investigation of any suspected fraudulent activity or Event of Default; and/or (vii) damages equal to your average monthly fees for the three (3) calendar months that your revenue was highest during the preceding twelve (12) months (or during the period of the Agreement if it has not been in effect for twelve (12) months), multiplied by the number of months then remaining in the term of the Agreement. You agree that any damages assessed by us are fair and reasonable because it is difficult or impossible to estimate our damages following an Event of Default, and that the pricing we extended to you assumed that you would use and pay for the Services during the entire Term. Notwithstanding the foregoing, any Improper Transaction shall result in immediate termination of this Agreement by us. Termination for any reason shall not relieve you of any liability or obligation you owe us. We have a right to assess fees and recover all costs associated with our investigation of suspected fraudulent activity or Event of Default. If you accept transactions in connection with an Event of Default, we have the right to hold settlement funds and to subject them to a per month fraudulent transaction fee equal to 15% of the amount held to offset our losses and anticipated losses. We have no liability to you for any direct or indirect losses you may suffer as a result of our suspension of funds disbursement or failure to pay transactions in connection with an Event of Default.
  2. Early Termination: If you terminate the Agreement prior to the end of the Initial Term, or if we terminate this Agreement due to inactivity as specified in Section 5.N of this Agreement or any other reason set forth in this Agreement, you shall pay us a fee to compensate us for early termination of the Agreement in the amount specified in the Merchant Application (“Early Termination Fee”) for each merchant identification number (“MID”) and Merchant location.
  3. Returning of Equipment/Materials: You shall return our equipment, promotional materials, advertising displays, emblems, Card drafts, credit memoranda, and other forms within 14 days of termination. You agree to immediately pay any amounts you owe for equipment. Without limiting the foregoing, if you fail to return equipment loaned to you by us within 21 days of termination of this Agreement or cancellation of your account for any reason, or if you return equipment in any damaged condition not due to normal wear and tear (in our sole discretion), we reserve the right to assess and collect from you the fair market value of the equipment, in our determination.
  4. Remedies: Our rights and remedies under this Agreement and/or at law or in equity are cumulative.
  5. Terminated Merchant FileDiscover Merchant ControlYou acknowledge and consent to our obligation to report your business name and the name of your principals to the Associations if we terminate you due to the reasons listed in the Operating Regulations, including for breaching this Agreement. You agree to refrain from bringing any claims against us for reporting you to the Associations.
  6. No Effect on LeaseTermination of this Agreement for any reason does not automatically terminate your equipment lease, if applicable.
  7. Effect of Termination: Upon termination of this Agreement for any reason at any time, you agree to pay us in addition to any other amounts required by this Agreement (i) any unpaid fees or invoices due; and (ii) any damages, losses, expenses, fees, fines, penalties, Chargeback amounts, and adjustments we incur in connection with the Agreement. You authorize us to debit your Designated Account to deduct amounts you owe us under this Section from the settlement funds we owe you, or to deduct such amounts from the Reserve Account. You are responsible for any collection fees, legal fees, and other expenses we incur in recovering your delinquent amounts.
  8. MATCH/TMF: You acknowledge that we may, in accordance with Association rules, add you, any person who signed the Application, and any Guarantor to Mastercard’s MATCH system, Visa’s Terminated Merchant File, and/or any other similar system or list.
  9. Reserved Authority of Associations: Processor may immediately terminate this Agreement if Processor is directed to do so by any Card Association, Network, or Member Bank. Card Associations may immediately terminate their services upon a Default Event, or any action the Association deems to be illegal, offensive or harmful to the Association. If the Association de-registers the Merchant, Processor, or Member Bank, this Agreement will automatically terminate.

10. Authorization, Setoff, Reserve, and Security Interest

  1. You authorize us, our agents, and third parties to initiate ACH credit/debit entries to or from the Designated Account, the Reserve Account, or any other account you maintain at any financial institution that is a member of an ACH Network, including for amounts you owe us, that we owe you, or for correction of errors, including but not limited to any liabilities or losses owed to us. This authorization applies even if and after you change the Designated Account. It survives the termination of this Agreement until the later of (i) two (2) years from the Agreement’s expiration; or (ii) the date you have satisfied all of your obligations to us. You shall ensure the Designated Account(s) have funds sufficient to satisfy your contingent and accrued obligations and duties under this Agreement. No attempt to change or alter the bank or deposit account you identify as the Designated Account (an “Account Change”) is effective until we acknowledge the change on our system. Accordingly, you shall not close a previous Designated Account until the new Designated Account receives its third deposit under this Agreement. We are not responsible for checking the accuracy of any Account Change your purported representatives submit in connection with an Account Change. Additionally, we are not responsible for liability associated with any Account Change unless it is due to our gross negligence or willful misconduct. You are solely liable for all fees and charges your financial institution assesses, including overdraft and non-sufficient funds charges. You release and hold us harmless from any financial institution fees or charges, regardless of cause. We are not liable for any delays in receipt of funds or errors in debit and credit entries caused by unaffiliated third parties, including the Associations, Other Networks, a clearinghouse, or your financial institution. We may audit and verify all Card and credits you accept. You agree that we may debit or credit your Designated Account for any inaccuracies. You also agree to be bound by the National Automated Clearing House Association’s operating rules.
  2. You agree that payment is due the date we originate an ACH debit transaction record to your Designated Account. Fees not paid when due bear interest at the rate permitted by law. You are responsible for paying all fees without setoff or deduction. We have the right to setoff amounts you owe us from amounts we owe you or your affiliates.
  3. The closing of your Designated Account does not constitute a mutually agreed upon termination of this Agreement, although it may be considered a termination of this Agreement by you.
  4. All funds resulting from transactions are held in a pooled clearing account (“Clearing Account”) with our banking partner. We will settle funds to and from the Clearing Account in the manner described in this Agreement; however, you have no rights to the Clearing Account or to any funds held in the Clearing Account, you are not entitled to draw funds from the Clearing Account, and you will not receive interest from funds maintained in the Clearing Accounts.
  5. In some circumstances based upon your processing history, your potential risk of loss to us or Member Bank as we may determine from time to time, your business type, your time in business, your financial information, your requested average/high ticket, your online reputation, or any combination of these or other similar factors, we may require you to create a reserve of funds (“Reserve Account”) in an amount determined in our sole discretion (“Reserve”). For example, and without limitation, we may require a Reserve if you have violated or are likely to violate this Agreement, or your account with us has an elevated or abnormally high number of Chargebacks or disputes, if we determine you are committing fraud or violating the Laws, or if you become subject to a civil, criminal, regulatory, or administrative investigation or litigation. If we impose a Reserve, we will establish the terms of the Reserve and provide you notice of the amount, timing, and conditions upon which the funds in the Reserve Account will be released to you. Unless otherwise specified by us or Member Bank in writing, the Reserve Account shall be fully funded upon three (3) days’ notice to you, or in instances of fraud or suspected fraud, an Event of Default, Reserve Account funding may be immediate. Reserve Account funding may occur by all or any combination of the following: (i) from settlement amounts, transaction proceeds, or any other amount otherwise payable to you; (ii) debits to any other accounts held by us or Member Bank; and/or (iii) your payment to us of the amount needed to fund a Reserve Account during this Agreement at the Reserve amount. We may change or condition the terms of the Reserve based on our continuous assessment and understanding of the risks associated with your account, including if required to do so by the Member Bank. We have the right to use any Reserve to cover any amounts due or that might become due to us at any time, including any amounts that remain unpaid after we debit (or attempt to debit) your Designated Account. Reserve Account funds may be commingled with other funds and need not be maintained in a separate account designated in your name. Subject to the other terms of this Agreement, we have the right and discretion to retain funds placed into the Reserve Account until the later of: (i) 270 days after the termination of this Agreement; (ii) 180 days after the last Card processing activity under this Agreement; or (iii) the conclusion of any pending criminal, civil, administrative, or regulatory investigation or litigation (the later of these three dates shall be the “Refund Request Date”). After the Refund Request Date, you must request in writing to receive the funds in the Reserve Account, and such request must include current information delivery of such funds.
  6. We or Member Bank, without prior notice to you, may deduct from the Reserve Account any obligation of you to us or Member Bank under this Agreement, including all Chargebacks, liabilities, losses, and any and all additional fees, and sums sufficient to reimburse Bank for the amount of any fines, penalty amounts, and charges due to the Card Associations.
  7. You shall not sell, assign, transfer, or encumber any part of your interest in the Reserve Account, or any present or future rights under this Agreement, including your right to receive payments or funds. Neither we nor Member Bank are obligated to honor any purported attempt to sell, assign, transfer, or encumber any interest, rights, or payments. In the event you breach this Section, we have the right to withhold funds payable to you, in addition to any other rights we may have at law or equity. You shall indemnify and hold us harmless from and against any claims, liabilities, and damages that any person (including a purported assignee) may assert against us arising out of your purported sale, assignment, transfer, or encumbrance of all or any of your present or future rights under this Agreement.
  8. This Agreement is a security agreement under the Uniform Commercial Code. You grant us a security interest in and lien upon all: (i) funds in the Designated Account; (ii) funds in the Reserve Account; (iii) amounts due you under this Agreement, including rights to receive payments or credits; and (iv) proceeds in any account or from any Card transaction (collectively, the “Secured Assets”), to secure all of your obligations under this Agreement. For Secured Assets maintained by Member Bank, you authorize Member Bank to comply with our demands regarding the Secured Assets. Our control of the Secured Assets with Member Bank constitutes a perfected interest under Article 9 of the Uniform Commercial Code. We may direct the disposition of the Secured Assets without further consent from you. You represent and warrant that we have the only security interest in the Secured Assets. You agree not to grant a security interest in the Secured Assets to a third party without our prior written consent. Additionally, we have a contractual right of setoff against the Secured Assets. Our right of setoff shall be deemed to have been exercised immediately upon the occurrence of an Event of Default without any action by us or notation in our records, even if we enter the setoff on our books and records at a later time.

11. Indemnification and Limitation of Liability

  1. You shall indemnify and hold us, and our directors, officers, employees, affiliates, and agents harmless from and against all proceedings, claims, demands, losses, liabilities, damages, and expenses (including any fines, fees, assessments, audit fees, card replacement costs, or penalties levied against us by an Association, any Card issuer, or any Other Network, and attorneys’ and collection fees and expenses) resulting from or otherwise arising out of: (i) your use of the Services; (ii) any breach of any term or condition of this Agreement; (iii) any misrepresentation by you under this Agreement and Application; (iv) your acts or omissions in connection with the Services under this Agreement, including the acts and omissions of your employees and agents; (v) your processing activities and provision of goods and services to Cardholders; (vi) any violation of the Operating Regulations or the Laws by you; (vii) any guarantees we provide to a third party for your benefit, including lease guarantees; (viii) any infiltration, hack, breach, or violation of the processing system resulting from, arising out of, or in any way related to your ability to use the Services, including your use of an Agent or any other third-party processor or system, or your ability to connect to the Internet or an external network; (ix) any act or omission of a third party with which you have contracted; (x) any bankruptcy proceeding; (xi) effecting transactions with the use of a lost, stolen, counterfeit, or misused Card; (xii) any action you institute against any Association, Other Network, or Card issuer following a Chargeback or fine; or (xiii) any action we take against the Designated Account, Reserve Account, or any other account you own, pursuant to this Agreement. You shall also defend, indemnify, and hold harmless the institution that maintains your Designated Account for acting in accordance with any instruction from us regarding the Designated Account. This indemnification shall survive the termination of the Agreement.
  2. EXCEPT FOR THOSE EXPRESS WARRANTIES MADE IN THIS AGREEMENT, WE DISCLAIM ALL WARRANTIES, INCLUDING ANY EXPRESS OR IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. You acknowledge and assume all risks associated with the acceptance of cards. We are not liable for lost profits, lost business, or any incidental, special, consequential, or punitive damages (whether or not arising out of circumstances known or foreseeable by us) you or your customers or any third party suffers in connection with the Services. We are not liable for damages or losses wholly or partially caused by you or your employees or agents. Nor are we liable for any damages or losses you may sustain as a result of our exercise of post-default rights or remedies under this Agreement, provided we had a good-faith, reasonable basis to believe an Event of Default occurred. Our liability related to or arising out of this Agreement shall not exceed the fees paid to us for the particular Services in question for the calendar month preceding the date of our relevant act or omission. The parties acknowledge that the limitations in this Section are integral to the amount of fees we charge for the Services. Except as otherwise described in this Section, your exclusive remedy for any claim against us is termination of the Agreement. We are not in default under this Agreement or liable for any delay or loss in the performance, failure to perform, or interruption of any Services resulting, directly or indirectly, from errors in data you or other parties provide to us, or any event beyond our reasonable control, including the Force Majeure Events defined below.
  3. We are not liable for, nor in default under this Agreement, for any delays, failure to perform, loss of performance, or interruption in service resulting directly or indirectly from a Force Majeure Event. A “Force Majeure Event” includes labor disputes; fire; weather; acts of God; acts of a public enemy; other casualty; pandemic; power outages; funding delays (however caused); governmental orders or regulations; errors in data provided by you or others; international, domestic, and/or economic terrorism; or any other cause, whether similar or dissimilar to those just mentioned, beyond our reasonable control.
  4. Except for actions related to your failure to pay amounts due under the Agreement, no cause of action shall be brought by either party more than one (1) year after it accrued.
  5. You recognize and agree that any limitations of liability set forth in this Agreement are fair and reasonable.
  6. Disputes With Cardholders: Merchant is solely responsible for settling any disputes between Merchant and its customers. Neither Processor nor Member Bank bears any responsibility for resolving or settling, such disputes. You shall not require a Cardholder to waive his or her rights to dispute the transaction as a condition of the sale..

12. Confidentiality

  1. We will be providing you with Confidential Information. “Confidential Information” includes information relating to our methods, techniques, programs, devices, and operations and those of Providers, the Associations, and Other Networks. You shall not disclose Confidential Information to any person or entity, other than to your employees and agents who participate directly in the performance of this Agreement and need access to the information. You agree to comply with the confidentiality and security requirements of the Laws and the Operating Regulations. This includes the Visa Cardholder Information Security Program found at https://usa.visa.com/partner-with-us/pci-dss-compliance-information.html; the Mastercard Site Data Protection Program, found at https://www.mastercard.us/en-us/business/overview/safety-and-security/security-recommendations/site-data-protection-PCI.html; and the American Express Data Security Operating Policy, found at https://www.americanexpress.com/us/merchant/us-data-security.html; and any similar Association or Other Network program requirement. You acknowledge receipt of our privacy notice, as applicable (“Privacy Notice”), which is incorporated by reference herein. Notwithstanding anything to the contrary in the Privacy Notice or this Agreement, we have the right to use, disclose, share, and retain any information you provide or that arises out of the Services, during the term and thereafter: (i) with your franchisor or franchisee(s), association(s) you belong to or belonged to at the commencement of this Agreement; (ii) with your affiliates; (iii) in response to subpoenas, warrants, court orders, or other legal processes; (iv) in response to requests from law enforcement or government agencies; (v) to comply with Laws; (vi) with our affiliates, business partners, and agents; (vii) to Associations and Other Networks and their designees, (viii) to Providers and their designees; (ix) to any other referral source or processor, including the applicable referrer, ISO/MSP, or independent Card office; (x) to perform analytic services for you, us, and/or others, including analyzing, tracking, and comparing transaction and other data to develop and provide insights for those parties as well as for developing, marketing, maintaining, and/or improving our products and services; and/or (xi) to offer or provide the Services under this Agreement. You authorize us to (i) make public the execution of this Agreement, this Agreement, and/or the provision of Services under this Agreement; and (ii) include your name and logo on a list of our customers that may be shared with the public. You agree to provide proof of compliance with the above upon request.
  2. You must secure and prevent the unauthorized access of any systems and media containing account, Cardholder, or transaction information (physical or electronic, including account numbers, Card imprints, and terminal identification numbers). Except for Card drafts you maintain in accordance with this Agreement or the Laws or Operating Regulations, you shall render inoperative and unreadable any media you no longer deem necessary or appropriate to store. You shall notify us of the identity of any third party who will have access to Cardholder data (“Merchant Provider(s)”). You shall also ensure that: (i) Merchant Providers cannot access Cardholder data unless authorized by the Operating Regulations; (ii) Merchant Providers have proper security measures to protect Cardholder data; (iii) you and Merchant Providers comply with the PCI DSS and PA DSS, as applicable; and (iv) you have written agreements with Merchant Providers requiring compliance with the terms of this Section. You shall immediately notify us of any suspected or confirmed loss or theft of any transaction information. This includes any loss or theft from a Merchant Provider. You are responsible for demonstrating your and Merchant Providers’ compliance with the PCI DSS and PA-DSS. You agree to provide us reasonable access to your locations and the locations of your Merchant Providers so that we can, at our option, verify whether you and your Merchant Providers can prevent future security violations. In the event of a suspected or confirmed loss or theft of information, you agree, at your expense, to provide any information, whether requested by us, an Association, financial institutions, or a local, state, or federal official in connection with the event. You further agree to cooperate in any ensuing investigation, including any forensic investigation. The information you provide in response to an investigation shall be considered our confidential information. The requirements of this provision apply to Cardholder data regardless of the medium in which the information is contained and regardless of whether you process transactions via internet, mail, phone, face-to-face, or any other method.
  3. Our proprietary and confidential online portal service provides reporting detail about your use of the Services (“Portal Services”). We reserve the right to disallow, discontinue, suspend, or change your use of Portal Services at any time without notice, including if we determine that you are committing fraud, violating the Laws, or are involved in any civil, criminal, regulatory, or administrative investigation or litigation. You agree to maintain the confidentiality of any Portal Services passwords in your possession. If we provide Portal Services to you, our only obligation is to make the Portal Services available in accordance with our standard operating procedures (e.g., then-current timeframes, standards, scheduling, and procedures, including those for setup, account access, and suspension of Portal Services). You shall provide us with prompt written notice of account or user ID changes, including User IDs that are no longer active or should be deleted. You are solely responsible for any unauthorized access to Portal Services, including unauthorized employee or agent access, or third-party access. We have no liability for third-party interruptions in Portal Services (e.g., internet providers), or errors or inaccuracies in the data reported to you.
  4. Merchant Identification Number. You are responsible for ensuring that your Merchant Identification Number (“MID”) is kept confidential. When a change to your Merchant Account is required, you must disclose your MID to the Processor representative to confirm that the person requesting the change has the authority to do so. If the person requesting the change discloses the proper MID, Processor or Member Bank shall assume that person has the proper authority to make the change. You shall be fully liable for any changes to your Merchant Account after disclosing the MID. Processor or Member Bank may request additional information from you to further verify your identity.

13. Continuing Unlimited Guaranty

This Section (“Continuing Unlimited Guaranty”) applies to each person who signs this Agreement as a guarantor (each a “Guarantor”). To induce us to enter the Agreement, each Guarantor jointly and severally guarantees the prompt and full payment of all Obligations (defined below) when due.

  1. “Obligation” means any obligation in the most comprehensive sense of the word. Obligation includes all indebtedness, debts, and liabilities (including principal, interest, late charges, collection costs, attorneys’ fees, and the like) that Merchant owes us including under this Agreement, whether Merchant created the obligation alone or with others, and whether Merchant is primarily or secondarily responsible. Obligations can be secured or unsecured, absolute or contingent, liquidated or unliquidated, and direct or indirect. Obligations can be evidenced by note, draft, a guaranty agreement, or otherwise. Obligations can exist now or arise in the future. It includes all payment obligations, indemnification obligations, and indebtedness Merchant owes us arising from or related to the transactions or Services under this Agreement.
  2. Guarantor promises to pay any Obligation that Merchant has not promptly paid when due. Guarantor promises to pay irrespective of our actions or inactions regarding the Obligations, or whether we have enforced any security interest created under this Agreement. Guarantor further promises to pay irrespective of the invalidity, insufficiency, or unenforceability of any Obligation. Guarantor’s obligations shall not be affected, modified, or impaired by any counterclaim, set-off, deduction, or defense based upon any claim the Guarantor may have against you (Merchant) or us, except payment or performance of the Obligations.
  3. Guarantor waives notice of any acceptances of this Continuing Unlimited Guaranty. Guarantor waives presentment, demand, protest, notice of protest, and notice of dishonor or other non-payment of any Obligations. Further, Guarantor waives notice of sale or other disposition of any collateral or security we now hold or later acquire. The duties of Guarantor shall not be released, discharged, or modified by (i) our extending the time for payment (for Merchant or Guarantor); or (ii) our delay or omissions in exercising any rights, taking any actions, or pursuing any remedies against Merchant or Guarantor. Guarantor agrees that we may release or modify any collateral, security, or other guaranties without notice or consent from Guarantor and without modifying Guarantor’s duties to us. This is a guaranty of payment and not of collection. We have no obligation to demand or pursue any rights against Merchant, anyone else (including another Guarantor), or to exhaust any rights or remedies related to any collateral, security, or other guaranties before demanding payment from Guarantor. Guarantor waives all defenses based on suretyship or impairment of collateral. Following a default under this Agreement, we may apply and/or set-off against amounts due to us any deposits, account balances, or other credits of Guarantor in our possession. Guarantor grants us a security interest in the items just described.
  4. The obligations of each Guarantor shall be joint and several with Merchant and any other Guarantor under this Agreement. The property described in any collateral security documents Guarantor provides, whether previously, contemporaneously, or in the future, secures this Continuing Unlimited Guaranty. This Continuing Unlimited Guaranty shall be binding upon and inure to the benefit of the parties and their respective heirs, executors, administrators, successors, transferees, and assignees.

14. Dispute Resolution, Governing Law, Jury Waiver, and Class Action Waiver

This Section applies to you, any Guarantor, or any other party who claims an interest in this Agreement.

  1. Dispute Resolution The parties will attempt to resolve any disputes relating to this Agreement in good faith and in a timely manner by mutual consultation. If a dispute remains unresolved for more than sixty (60) days, then such dispute shall be resolved as set forth in Section 11.B of this Agreement. Nothing in this Section 14.A prohibits a party from applying to a court of competent jurisdiction for a temporary restraining order, preliminary injunction, or other equitable relief at any time.
  2. Governing Law/Jurisdiction: The parties have entered into this Agreement in California. The laws of California govern the interpretation, construction, and enforcement of this Agreement, including the Continuing Unlimited Guaranty. We, you, and each Guarantor agree to bring any legal suit, action, or proceeding arising out of or related to this Agreement, the Services, or pertaining in any way to the relationship between us and you, or us and Guarantor, each an “Applicable Claim,” in state or federal court located in Orange County, California. With respect to any Applicable Claim brought by us, you or Guarantor, you/Guarantor waive any objection to venue and submit to the personal jurisdiction of the courts located in Orange County, California. You/Guarantor agree that our service of any summons and complaint at the address listed in the Agreement constitutes proper service and subjects you/Guarantor to the personal jurisdiction of the courts located in Orange County, California. Unless the Operating Regulations require otherwise, you shall bring any claim you have against Member Bank against us (subject to the limitations and restrictions of the Agreement), and not against Member Bank.
  3. Jury: WE, YOU, AND GUARANTOR KNOWINGLY, VOLUNTARILY, AND INTENTIONALLY WAIVE ANY RIGHT TO HAVE ANY APPLICABLE CLAIM OR OTHER CLAIM ARISING OUT OF THIS AGREEMENT OR THE SERVICES DECIDED BY A JURY. YOU AND/OR GUARANTOR AGREE THAT OUR FILING OF A COPY OF THIS PARAGRAPH IN ANY PROCEEDING CONCLUSIVELY PROVES YOUR WAIVER AND THE WAIVER BY GUARANTOR.
  4. Class Action Waiver: YOU AND GUARANTOR WAIVE ANY RIGHT TO PARTICIPATE, AS A NAMED CLASS REPRESENTATIVE OR NAMED PLAINTIFF, IN A CLASS ACTION AGAINST US OR MEMBER BANK IN CONNECTION WITH THIS AGREEMENT OR THE SERVICES.

15. Funding Time

If you request and are approved for Next Day Funding, Same Day Funding, or any accelerated funding time we will generally initiate an ACH of settlement funds due to you to the Designated Account within one business day (i.e., any day Federal Reserve Banks are open for business), or the appropriate time frame for accelerated funding, provided we receive the complete transaction data by the applicable cutoff time. We have no liability to you if we do not ACH your settlement funds within one business day or the appropriate time frame for accelerated funding. If you are not approved for Next Day Funding, Same Day Funding or accelerated funding we will set you up with Premium ACH for your deposit timeframe. We can, at our sole discretion, change your deposit timeframe from Next Day Funding, Same Day Funding, or accelerated Funding to Premium ACH or a funding time of our choosing without notice. We can also, in our sole discretion, delay your settlement payments for up to thirty days from the date we received the settlement payment. This does not preclude us from exercising our right to establish a Reserve Account or to suspend payments pursuant to other provisions of this Agreement. On the next business day following the expiration of the delay period, we will begin crediting the settlement payments to your Designated Account, less any amounts you owe us. This delay of the settlement payments will be ongoing and will continue as long as we are providing you with processing Services (i.e., it will be a rolling delay). Additionally, we have the right to delay, in our sole discretion, crediting the Designated Account with funds evidenced by submitted Card transactions. You are responsible for verifying the amount of funds actually deposited to and available in your Designated Account on a daily basis. We are not responsible for the availability of funds represented by submitted Card transactions, or for any charges you incur for overdrawing the Designated Account.

16. Security Services

Security Services may individually or collectively mean EMV Support, PCI Program, and point-to-point encryption (“P2PE”), or such other service as designated by us. You may utilize P2PE products and services on select terminals using services provided wholly or partially by a third party with our support (collectively referred to as “Security Services”). You bear all risk and responsibility for conducting your own due diligence regarding the fitness of Security Services for a particular purpose and for determining compliance with the Operating Regulations and the Laws. Accordingly, your use of Security Services is at your own risk. Our decision to offer Security Services shall not limit your duties and obligations contained in this provision or the Agreement. You acknowledge that the receipt of Security Services may require the use or upgrading of certain terminals and/or equipment or new message specifications (which shall be at your sole expense) and may not be supported on all terminals/equipment. We do not warrant or guarantee that use of the Security Services, in itself, will: (i) result in your compliance with Operating Regulations and/or Laws; (ii) prevent any and all unauthorized breaches of your terminals, systems, or facilities; or (iii) be uninterrupted or error-free. You shall not acquire any interest in (ownership, intellectual property or otherwise) any of the third-party provider software used to provide the Security Services. You shall not, and shall have no right to, own, copy, distribute, sub-lease, sub-license, assign or otherwise transfer any portion of such third-party provider software used to provide the Security Services or any materials provided by us or to modify, decompile, or reverse engineer any such software, materials, or the Services.

  1. EMV Support: Europay, Mastercard, and Visa (“EMV”) is a set of global standards for credit, debit and contactless card payments. EMV chip cards help prevent in-store fraud and are nearly impossible to counterfeit. If you have not made the investment in chip-enabled technology, you may be held liable for card-present EMV acceptance requires an EMV enabled standalone terminal or POS system. We are enabled to process in-store EMV transactions to help reduce fraud liability.
  2. EMV Non-Enabled Fee The EMV Non-Enabled Fee is effective if you do not have EMV enabled equipment and/or software. The EMV Non-Enabled Fee is determined based on the Chargeback liability risk of your MCC as determined by us. Transactions will be evaluated and assessed monthly at the MID level. This fee is based on the gross sales amount of each card present transaction.
  3. Point to Point Encryption: The P2PE Service is a two-part service designed to (i) encrypt (make unreadable) Card data information at the origin of the payment transaction, which is a PCI-approved secure cryptographic device (“SCD”) that has licensed P2PE functionality that aligns with the P2PE technologies hosted by us; and (ii) decrypt card data information at the destination of the transaction, which are our data systems. You acknowledge and agree that SCD P2PE functionality is required and may require you to engage an appropriate third-party provider or authorized reseller, and said licensed functionality may incur fees in addition to those set forth herein. Card data information protected by the P2PE Service may include Track 1 or Track 2 data (i.e., Card data obtained through a Card swipe read) or PAN data (i.e., manually entered personal account number Card data) as appropriate to the type of transaction processed. The SCD functionality supporting the P2PE Service is designed to securely store or generate encryption keys which are used in conjunction with the P2PE functionality to encrypt card data at the moment that the card data is captured by the SCD. The P2PE Service applies only to transactions that were encrypted by the SCD and sent from the terminal to our authorization and settlement systems pursuant to the Agreement. Supported transactions include those associated with credit (signature), debit (signature), and debit (personal identification number, “PIN”). Our provision of P2PE Service to you is subject to the availability of the licensed encryption software from the applicable third-party provider and your compliance with the Agreement.
  4. PCI ProgramThe Card Organizations have mandated that all merchants must comply with the PCI DSS found at pcisecuritystandards.org (see www.visa.com/cisp for additional information). We have a program to assist merchants with PCI DSS validation (“PCI Program”). Member Bank is not a party to or liable for PCI Program.
  5. Benefits of PCI ProgramUpon enrollment in the PCI Program, you are eligible to receive:
    1. Access to an online PCI Certificate validation system, where you can complete your SAQ;
    2. Access to remote scanning services, which include monthly vulnerability scanning for up to five (5) of your computer website IP addresses (additional fees apply if you have more than five IPs). This applies to PC/IP merchants only; and
    3. Access to https://123pci.pcicompliance.ws
  6. PCI Compliance Validation Process:
    1. Validation Requirement:In order to take full advantage of the PCI Program, you must validate your compliance with the PCI DSS on an annual basis or as otherwise required by us or a Card Organization. To validate your compliance with the PCI DSS, you must successfully complete a SAQ and, if applicable, a vulnerability scan as provided below.
    2. Self-Assessment Questionnaire (“SAQ”): A SAQ is a list of questions developed by the PCI Security Standards Council.
    3. Vulnerability Scan (“Scan”): A vulnerability scan is necessary for PC, IP enabled terminal, or integrated ECR merchants. Here are the steps to receive your Scan:
      • Once you have completed your SAQ, the system will guide you to schedule a Scan, if applicable.
      • The Scan will identify vulnerabilities or gaps that may allow unauthorized or malicious users to gain access to your network and potentially compromise cardholder data. The Scan does not require you to install any software, and no denial-of-service attacks will be performed.
      • Upon completion of the Scan, you will receive a link to your full compliance report. A network vulnerability review failure means that the Scan discovered areas of severe vulnerability. The report describes the issues found and provides you with recommendations for scan resources to begin fixing the problems. The tool will guide you to remediate the failed Scan and work toward achieving compliance. Once you have addressed the vulnerabilities, simply schedule a follow-up Scan to ensure your remediation of the problem meets the PCI DSS requirements.
    4. Certificate of Validation: Upon successful completion of the SAQ and Scan, if applicable, your Certificate of Validation will be issued. You can print your Certificate through our online portal or, if you have completed a paper version of the SAQ, your Certificate will be mailed to you.
    5. Re-Validation:  You must maintain a current, successfully completed SAQ and timely pass quarterly Scans, if applicable, in order to take full advantage of the PCI Program. An SAQ is no longer current if the Certificate of Validation issued by us to you is more than one (1) year old. You are also required to re-validate by completing a new SAQ and passing Scans, if applicable, when you make a change in your processing environment or if you fail to timely complete a required quarterly Scan.
      • A change in your processing environment requiring re-validation occurs when you transition from one card-processing environment to another such that your SAQ Classification changes, necessitating re-validation under a new SAQ. With respect to a re-validation required due to a change in your processing environment, you must complete the re-validation process within twenty-four (24) hours of such change in order to maintain your validation of compliance with the PCI DSS.
      • With respect to a re-validation required due to your failure to complete a required quarterly Scan, we will deem your failure to complete a Scan within ten (10) days of the end of the preceding quarter to require re-validation under the PCI Compliance Validation Process, in order to maintain your validation of compliance with the PCI DSS.
      • With respect to a re-validation required due to the expiration of the annual SAQ or any other reason for which Re-Validation is required, you will have five (5) days to complete the PCI Compliance Validation Process, in order to maintain your validation of compliance with the PCI DSS. Once you have successfully completed the re-validation of your PCI DSS compliance, we will issue you a new Certificate of Validation for the current validation period.
  7. Costs: We may assess you, at our sole discretion, a monthly non-compliance fee of $19.95 if you do not validate your compliance with PCI DSS.
  8. Security Policy As part of PCI DSS, the Card Organizations require that you have a security policy that covers the security of credit card information.
  9. Amendment: The Security Services is subject to change from time to time by us. Any changes will be effective fifteen (15) days following the date notice of such change is sent to you, even if it was not received by you.
  10. Further Information: To speak with our customer service representative, please call us at 1-866-849-2445.
  11. Waiver: Limitations on Waiver:  Upon your successful validation of compliance with the PCI DSS under the PCI Program, we agree to waive your liability to us, up to $50,000, for the following fees and costs incurred as a result of a verified compromise of cardholder data that are otherwise your liability under this Agreement: (1) fees and costs associated with a required forensic audit conducted by an approved Qualified Incident Response Assessor (QIRA); (2) fines or assessments levied by a Card Organization as a result of the required forensic audit; and (3) fees and costs associated with the production and distribution of replacement credit cards for compromised card numbers (the “Waiver”).

  1. The Waiver provided under this Section is also subject to the following:

    1. Our agreement to waive your liability to us for the fees and costs described in this Section is only effective upon (1) your continued validation of compliance with the PCI DSS and participation in the PCI Program; and (2) your successful completion of the PCI Compliance Validation Process described in Section 16.F. above; provided, however, that there is no change in your business practices regarding Card acceptance. Your continuing qualification for the PCI Program is premised upon initial validation of your compliance with the PCI DSS and timely re-validation of your compliance with the PCI DSS, including annual completion of a SAQ and passing quarterly vulnerability Scans, if applicable, payment of the PCI Program cost, and otherwise complying with the terms of the PCI Program and the Agreement.
    2. If you are in compliance with the requirements of subsection (i) above, we agree to waive up to $50,000 in fees and costs described in this Section for each unique MID. If you have multiple MIDs that have the same federal tax identification number (or in the case of a sole proprietorship, the same social security number), then the maximum aggregate Waiver amount for those MIDs is limited to $700,000. In addition, if a MID is one of a group of MIDs that are eligible for and receive a multi-merchant discount for the PCI Program fees, the aggregate Waiver for all MIDs in such group is $700,000.
    3. Your validation of compliance with the PCI DSS through the PCI Program is required to be eligible for the Waiver. You will not be eligible for the Waiver if your SAQ is not current, if you have not timely completed the quarterly vulnerability Scans, or if you have otherwise failed to maintain compliance with the PCI DSS through the PCI Program.
    4. The Waiver of up to $50,000 described in this Section is limited to one (1) compromise of Cardholder data incident per PCI Program year. Any subsequent incidents occurring during the same PCI Program year are not eligible for the Waiver, and any costs and fees associated with such incident(s) remain your liability under this Agreement. Chargebacks are not eligible for the Waiver under any circumstances.

17. Representations and Warranties

You represent and warrant that:

  1. InformationAny information you have submitted to us is true, complete, and accurate. This includes information about your entity type, the nature of your business (e.g., products and services sold, manner of sale, etc.), and the financial condition, ownership, and executive structure of your business.
  2. Corporate PowerYou and any person signing the Application on your behalf have the power to execute this Agreement and to perform under this Agreement. The person signing the Application may execute any future documents and take any future action on your behalf.
  3. Existence/OrganizationYou are a person or an entity validly existing and organized in the United States.
  4. No Litigation: You have no knowledge of an actual or threatened action, suit, investigation, or proceeding against you that might impair your financial condition or prevent you from operating your business as you now conduct it. You have never appeared on Mastercard’s MATCH system or Visa’s Terminated Merchant File or any combined terminated merchant file, except as already disclosed in writing.
  5. Transactions: The Card transactions you submit to us: (i) represent the obligations of the authorized Cardholder for merchandise or services actually sold, rented, or rendered (except for any delayed delivery or advance deposit authorized by the Rules) and must not involve any element of credit for any other purpose; (ii) represent bona fide Card/rentals of merchandise and/or services not previously submitted and do not represent a refinancing of any prior obligation; (iii) are not subject to any dispute, setoff, or claim against the price; (iv) are not, to your knowledge or notice, fraudulent, unauthorized by the Cardholder, or subject to any other infirmity or impairment; and (v) do not result from any sale outside your normal course of business, as described in the Application.
  6. Products and ServicesThe following items are true: (i) you have complete power and authority to sell the products and services you offer and to display the advertisements you use; (ii) your products and services are not illegal, nor are they a product or service that is patently offensive and lacks serious artistic value, and you will not accept a Card for any illegal transaction; (iii) you will prominently and unequivocally inform each Cardholder of your identity at all points of interaction during the transaction to distinguish you from any other party; (iv) your products, services, and business name do not infringe upon the rights of any other person, including trademark, copyright, confidentiality, or patent rights; and (v) you will not sell, market, or display any products or services that would violate any Law or jeopardize our reputation. You shall provide to us information to support the representations regarding your products, goods, and services, including copies of your sales and marketing materials, online advertisements, proof of delivery documents for tangible goods, and proof of services provided for services. All such information shall be provided to us within three (3) business days from and in the form specified in our request.
  7. Debit EBT Card Processing Services: Availability of Terminals: We will process Debit Card transactions for you if indicated in the Application or an amendment. If you accept EBT Cards, the terms in Addendum A shall apply. We will provide sponsorship services to you (through a third party bank), if applicable. You will take all steps necessary to ensure that POS devices and PIN pads will be available for Cardholder use and will function in a reliable manner.
  8. Wireless OperatorYou hereby authorize your wireless operator (AT&T, Sprint, T-Mobile, US Cellular, Verizon or any other branded wireless operator) to use your mobile number, name, address, email, network status, customer type, customer role, billing type, mobile device identifiers (IMSI and IMEI) and other subscriber status details, if available, to allow verification of your identity and to compare information you have provided to us with your wireless operator account profile information for the duration of the business relationship.

18. Surcharge, Cash Discount, Dual Pricing

  1. Surcharge Program. If Merchant chooses to impose a surcharge on Card payments, Merchant may do so only after meeting specific considerations, limitations and requirements as defined by the Card Associations.

    1. Merchants electing to implement a surcharge program may assess a fee of no more than three percent (3%) on credit card transactions only (or as otherwise permitted by applicable law, if less). Surcharges shall not be applied to debit card or prepaid card transactions under any circumstances.
    2. All required surcharge disclosures must be: Posted at the point of entry to the merchant’s business; Displayed on the merchant’s website (if applicable); Clearly presented at the point of sale; and Printed on all transaction receipts, including the required disclosure verbiage.
    3. Merchants must provide their acquirer with thirty (30) days’ prior written notice before implementing surcharging. For purposes of this Agreement, LUQRA, shall constitute the Merchant’s acquirer, and no further notice shall be required.
  2. Prohibited States & Additional Requirements

    1. Surcharging is prohibited in the following states: Connecticut, Maine, and Massachusetts.
    2. Merchants located in California and New York are subject to additional disclosure requirements. Specifically, merchants must display the maximum price on the product, shelf, or menu that reflects the total amount a consumer may pay regardless of payment method.
    3. Merchants in Oklahoma electing to implement a surcharge program may assess a fee of no more than two percent (2%) on credit card transactions only. Surcharges shall not be applied to debit card or prepaid transactions under any circumstances.
  3. Dual Pricing and Cash Discount Programs

    1. If implementing dual pricing or a cash discount program, the cardholder must be presented with a “regular price,” with any applicable discount shown on the receipt when cash is the chosen form of payment.
    2. Pricing displays must not reference “card” or “credit” as the basis for price differences. Instead, the regular price must be presented as the standard price, with a discount shown when customers pay in cash.
  4. Merchant Acknowledgment and Compliance

    1. Merchant acknowledges receipt of these requirements and certifies that it will strictly comply with all applicable rules, regulations, and card brand requirements regarding surcharging, dual pricing, and cash discount programs.
    2. Merchant understands and agrees that failure to adhere to these requirements may result in termination of program participation and/or the imposition of non-compliance assessments, including fines and penalties.
  5. Legal Disclaimer

    1. LUQRA is not a law firm and does not provide legal advice. Merchant has had the opportunity to review these terms and the applicable programs with legal counsel of its choice to confirm legality within the jurisdiction(s) in which it operates.
    2. Merchant agrees that it is solely responsible for ensuring compliance with all applicable laws, regulations, and card brand rules.
  6. Limitation of Liability

    1. Merchant expressly waives any and all claims it may have against LUQRA relating to or arising from participation in any surcharge, dual pricing, or cash discount program, including but not limited to compliance with applicable rules and regulations.

19. Miscellaneous Terms and Conditions

  1. Headings and ConstructionThe parties have used the headings in this Agreement for convenience only. No heading shall affect the interpretation of any Terms and Conditions, which are subordinate to the Operating Regulations and the Application (unless the Application is blank). Our approval of the Application does not guarantee you a right to receive processing. The parties have chosen the language in this Agreement to express their mutual intent. No rule of strict construction shall operate against any party. This Agreement constitutes the entire agreement between the parties with regard to the Services and supersedes all prior or other agreements or representations regarding the Services, whether written or oral. All prior understandings have merged into this Agreement.
  2. Other Rights and AcknowledgementsWe may change Member Banks at any time without notifying you. Any Member Bank may delegate all or part of its duties to its affiliate at any time, also without notifying you. We are an agent of Member Bank in connection with Visa and Mastercard transactions and may use an ISO/MSP in connection with this Agreement. The ISO/MSP is an independent contractor and not our agent. Accordingly, ISO has no authority to execute an Agreement on our or Member Bank’s behalf. You owe Member Bank the same obligations you owe us. We may exercise any rights or remedies in this Agreement individually or jointly with Member Bank and may likewise exchange or allocate the duties and obligations each owes to you.
  3. Attorney’s FeesYou shall pay us for all attorneys’ fees and other costs and expenses we incur or pay in: (i) defending our rights under this Agreement; (ii) enforcing the Agreement; or (iii) collecting any amounts you owe us under the Agreement. In the event of a lawsuit under this Agreement, the prevailing party shall be entitled to its reasonable attorneys’ fees and costs.
  4. SurvivalProvisions that impose or could impose a continuing obligation on you shall survive the expiration or termination (for any reason) of this Agreement. This includes your liability for Chargebacks and reversals, your duty to indemnify us and Member Bank, and your duties with respect to account maintenance.
  5. Association/Other Network: You may sign an agreement with an Association or Other Network ("Other Merchant Agreement"). Each Other Merchant Agreement is a separate and independent agreement. We have no responsibility for Association’s, Other Networks, or your breach of an Other Merchant Agreement. We do not have to comply with the terms or conditions of an Other Merchant Agreement. We have a right to cease providing Services for any Other Networks or Associations in our sole discretion. You agree to pay all fees, fines, assessments, and penalties the Associations or Other Networks impose. We may allocate any such fees, fines, assessments, or penalties imposed on us in any manner and in our sole discretion. You agree that all POS terminals operate with unique keys according to Network requirements.
  6. RoutingYou authorize us to decide where to route a Card transaction.
  7. Non-Discrimination: If applicable, we and you shall abide by the requirements of 47 CFR § 60-1.4(a), 60-300.5(a) and 60-741.5(a). These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their color, race, religion, sex, or national origin. Moreover, these regulations, if applicable, require each of us to take affirmative action to employ and advance in employment individuals without regard to race, color, religion, sex, national origin, protected veteran status or disability.
  8. Title to the ServicesYou agree that the Services are licensed and not sold. As a result, you only acquire a nontransferable, revocable, non-exclusive right to use the Services. The right exists only during the term of the Agreement, and only for the purpose of accepting and managing payments. We retain all rights, title, and interest in and to the Services. This includes rights in materials we deliver to you, and any invention, development, product, trade name, trademark, service mark, software program, or derivative from any item just listed. You shall not: (i) copy, reproduce, alter, modify, create derivative works, publicly display, republish, upload, post, transmit, resell, or distribute any of our material; (ii) permit any third party to use or benefit from the Services through a rental, lease, timesharing, service bureau, or other arrangement; (iii) work around, bypass or circumvent any of the technical limitations of the Services, use any tool to enable disabled functionalities, or decompile, disassemble, or reverse engineer the Services (unless the restriction is prohibited by the Laws); (iv) perform any act that interferes with proper access or use of the Services; or (v) use the Services in any manner not expressly allowed under this Agreement.
  9. NoticesUnless otherwise stated, you shall deliver notices and other communications in writing via certified mail or reputable overnight courier (postage prepaid) to the following address: Luqra, Attention: Legal, 4100 Newport Place Drive, Suite 500; Newport Beach, CA Notices delivered in this manner become effective upon our actual receipt. Our communications to you shall be delivered via email, facsimile (effective upon transmission confirmation), ordinary or certified mail (effective the seventh day after mailing), reputable overnight courier (effective the first day after submission to the courier), or via a report, communication via Portal Service or invoice (effective when made available).
  10. No Obligation to ProcessWe have no obligation to process any Visa or Mastercard transaction beyond the authority of a U.S. member of Visa and Mastercard or any Discover or American Express transaction outside the United States and other United States territories.
  11. Account Debiting Authorization: In addition to our other collection rights in this Agreement, you expressly authorize us or our affiliate to collect amounts due us or our affiliate by debiting any deposit account you maintain or have on file with us or Member Bank.
  12. Amendments: We may amend this Agreement or change rates at any time. You do not have the same right. We will provide notice of changes in accordance with the notice Section of this Agreement. If you continue to process transactions after, or fail to notify us that you contest a change within seven days of actual or constructive notice, you will be deemed to have accepted that change. We have the right to make Association and Other Network changes and increases in interchange, fees, or assessments without providing you notice. You agree to pay these increased fees and charges throughout the term. We are not bound by any changes, additions, or deletions you make to the Agreement unless they are part of a written amendment that is signed by you and us. Notwithstanding anything in this Agreement to the contrary, we reserve the right to correct minor typographical or other errors that do not affect the material content of this Agreement without recourse.
  13. Assignment: We have a right to assign this Agreement. Unless you obtain our prior written consent, you do not. This means that any assignment, even an assignment by operation of law, is prohibited without our consent. This Agreement shall be binding upon and inure to the benefit of the parties and their respective heirs, executors, administrators, successors, transferees, and assignees (if applicable). If you assign this Agreement without our consent, the assignee will be bound by the terms of this Agreement, and we reserve the right to pursue remedies for an Event of Default as set forth in herein. Your sale of the business does not relieve the original owner or original Guarantors of Chargeback or other liabilities, even those occurring after sale.
  14. Independent ContractorsWe are not your agent, and we are not in a joint venture, or partnership with you (or vice-versa). We and you are independent contractors.
  15. No Third-Party Beneficiary: Unless expressly stated in these Terms and Conditions, this Agreement is for the benefit of, and may be enforced by, only you and us, and our successors and permitted transferees and assigns. It is not for the benefit of any third-party.
  16. Employee and Agent Actions: You are responsible for the acts or omissions of your employees, independent contractors, and agents related to this Agreement and the use of the Services.
  17. Severability and Non-WaiverThe invalidity or illegality of any part of this Agreement shall not invalidate the rest of the Agreement. The Agreement shall instead be construed as if the invalid or illegal provision were not part of the Agreement. Our delay or failure to exercise any right under this Agreement shall not operate as a waiver or estoppel of that right.
  18. SignatureAn original, a copy, facsimile copy, or digital, photographic or electronic copy of your signature serves as the signature for this Agreement. Further, duplicate original records of this Agreement (digital, photographic, or otherwise) have the same force and effect as the original. The parties agree that contracting through electronic means including e-signature or "click to agree" processes is an acceptable form of showing and proving mutual assent to this Agreement.

20. Investment of Funds

To the extent permitted by applicable law and the Operating Regulations, Processor and/or Member Bank may hold Merchant Settlement Funds in pooled, commingled accounts and may sweep or invest such balances in liquid investments. All earnings (including interest) on such holdings belong exclusively to Processor, and no interest is payable to Merchant. No trust or fiduciary relationship is created; Merchant’s rights are contractual only to receive settlement as provided in this Agreement, net of fees, setoff, Reserve, and other adjustments.

21. Additional Definitions

The following terms shall have the meaning specific below when used in this Agreement. Certain other capitalized terms are defined elsewhere in this Agreement in the context of the provision in which they are used.

“ACH” means an electronic funds transfer processed through one of the automated clearing house systems and subject to the Nacha Network Rules.

“Agreement” means the Merchant Processing Agreement (including Terms and Conditions), Merchant Application, Operating Regulations, and any attached addenda, exhibits, schedules, or other documents.

“Application” and “Merchant Application” mean either the physical/virtual form or the act of making an application by providing information via a web page user interface to obtain Service from us.

“Associations” means, collectively, Mastercard, Inc. (“Mastercard”), Visa, Inc. (“Visa”), Discover Financial Services (“Discover”), and American Express Company (“American Express”), each including its applicable affiliates and payment networks, and certain similar entities.

“Card(s)” means Association or Other Network branded cards that enable consumers to purchase goods and services from Merchants.

“Cardholder(s)” means persons authorized to use Association or Network branded cards.

"Change in Control" means the consummation by Merchant of a transaction or series of transactions in which any one or more of the following occurs: (1) any person becomes the beneficial owner, directly or indirectly, of 25% or more of Merchant’s business; (2) the sale, lease, exchange, or other disposition of 25% or more of all of Merchant’s consolidated assets; or (3) a complete liquidation or dissolution or a plan of complete liquidation or dissolution of Merchant.

"Chargeback" means a Transaction for which payment has been refused or reversed in accordance with the Operating Regulations. The term also means, where appropriate, a Card reject or any other credit or return initiated by a Merchant’s customer or Card issuing bank.

“Clearing Account” has the meaning set forth in Section 10.D.

“Confidential Information” has the meaning set forth in Section 12.A.

“Designated Account(s)” has the meaning set forth in Section 7.A.

"Discount Rate" means a percentage of the total transactions submitted to Member Bank for processing.

“Early Termination Fee” has the meaning set forth in Section 9.B.

"Effective Date" means the later of (i) the date you signed the Application; or (ii) the date we approved the Application.

“Event of Default” has the meaning set forth in Section 9.

“Excessive Activity” has the meaning set forth in Section 5.M.

“Excessive Activity Fee” has the meaning set forth in 5.M.

“Improper Transaction” has the meaning set forth in Section 9.A.

“Initial Term” has the meaning set forth in Section 1.A.

"ISO/MSP" means an independent sales organization/member service provider operating under the Operating Regulations.

"Laws" means all applicable state, federal, and local laws, rules, and regulations.

"Member Bank" means a member of Visa, Mastercard and/or Other Networks, as applicable, that provides sponsorship services in connection with this Agreement.

"Operating Regulations" means the Association and Network bylaws, operating regulations, rules, policies and procedures. The Operating Regulations may be changed or updated from time to time without notice.

"Other Networks" or "Networks" means, collectively, all our supported payments networks not defined above as Associations.

“Per Item Fee(s)” has the meaning set forth in Section 7.B.

“Portal Services” has the meaning set forth in Section 12.C.

“Processor VAMP Threshold(s)” means the risk thresholds, limits, and criteria (including ratio and/or count-based limits) that Processor applies to Merchant’s VAMP Metrics for risk management purposes, as set forth in Processor’s VAMP Threshold Fee Schedule, which may be more restrictive than Visa’s published thresholds. Unless Processor provides notice of different Processor VAMP Thresholds in accordance with this Agreement, the Processor VAMP Ratio threshold for Merchant is 0.50% (50 basis points) per monthly period (the “Processor VAMP Ratio Threshold”).

“Reserve” has the meaning set forth in Section 10.E.

“Reserve Account” has the meaning set forth in Section 10.E.

"Service" means any services described in this Agreement and/or provided by us.

“VAMP” means Visa’s Acquirer Monitoring Program, which consolidates Visa’s fraud and dispute monitoring programs, as defined by Visa in Visa Operating Rules and associated publications (including any successor or replacement program).

“VAMP Metrics” include (a) the VAMP Ratio, (b) the Enumeration Ratio (ratio and transaction count), and (c) any other associated minimum counts and thresholds, including Excessive Merchant Thresholds, as defined and published by Visa, and the Processor VAMP Thresholds.

Exhibit A: Association-Specific Addenda

Exhibit A: Association-Specific Addenda

1. Discover Network

A. Marks Policy: Merchant is prohibited from using the Program Marks, as defined below, other than as expressly authorized in writing by Acquirer. Program Marks mean the brands, emblems, trademarks, and/or logos that identify Discover Cards, including, without limitation, Diners Club International Cards. Additionally, Merchant shall not use the Program Marks other than to display decals, signage, advertising, and other forms depicting the Program Marks that are provided to Merchant by Acquirer pursuant to the Merchant Program or otherwise approved in advance in writing by Acquirer. Merchant may use the Program Marks only to promote the services covered by the Program Marks by using them on decals, indoor and outdoor signs, websites, advertising materials and marketing materials; provided that all such uses by Merchants must be approved in advance by Acquirer in writing. Merchant shall not use the Program Marks in such a way that customers could believe that the products or services offered by Merchant are sponsored or guaranteed by the owners of the Program Marks. Merchant recognizes that it has no ownership rights in the Program Marks. Merchant shall not assign to any third party any of the rights to use the Program Marks.

2. Mastercard

A. Marks Policy: Each Merchant that accepts Mastercard must comply with the following governing the use of Mastercard and your marks, and any other policies outlined in the Mastercard Operating Regulations. You agree that (i) any use of a Mark by a Merchant in advertising, acceptance decals, or signs, must be in accordance with the Operating Guidelines, including Mastercard’s reproduction, usage, and artwork Standards, as may be in effect from time to time; and (ii) The Merchant’s use or display of any Mark will terminate effective with the termination of the Merchant Agreement, or upon notification by the Corporation to discontinue such use or display.

Other acceptance marks, symbols, logos, or combinations thereof may appear in the same material or image with the Acceptance Marks, provided visual parity is maintained and no other acceptance mark, symbol, or logo displayed is more prominent or likely to cause confusion concerning the acceptance of Cards. Each Acceptance Mark must be displayed as a free-standing mark, meaning that an Acceptance Mark must not be displayed so as to suggest that it is either a secondary means of payment or exclusively linked to another acceptance brand.

Mastercard may from time to time use publicly available business information pertaining to a Merchant. For purposes of example and not limitation, such information may include business logos, geographic mappings of physical business addresses, publicly disclosed contact information, sales policies, and other such publicly available business information. Mastercard may: (i) Make the Merchant business logo and other information available to Issuers in order to enrich the posting of Transaction data to Cardholders; and/or (ii) Directly or through its partners, use the Merchant business logo in digital apps, websites, or other tools designed to enable Cardholders to obtain Merchant information, including but not limited to locating the Merchant's physical business address and confirming the identity of a Merchant with which the Cardholder has transacted.

3. American Express

The following terms apply only to Merchant’s participation as a Program Merchant in the American Express OptBlue Program (the “Program”). All capitalized terms under this section that are not defined in this Agreement shall be given the definition set forth by American Express. In the event of any conflict between any term(s) defined by American Express and any term(s) defined in this Agreement, the term defined by American Express shall control. Merchant agrees to comply with (i) all Applicable Laws, rules, and regulations relating to the conduct of Merchant’s business, and (ii) the American Express Merchant Operating Guide, as may be amended from time to time, which is incorporated herein by reference and found at https://icm.aexp-static.com/content/dam/gms/en_us/optblue/us-mog.pdf.

  1. Merchant authorizes Processor (or Member Bank) to submit Transactions to and receive settlement from American Express on Merchant’s behalf.
  2. Processor (or Member Bank) may (i) collect and disclose Transaction Data, Merchant Data, and other information about Merchant to American Express, (ii) use such information to perform its responsibilities in connection with the Program, promote the American Express Network, perform analytics and create reports and for any other lawful business purpose, including commercial marketing communications purposes within the parameters of this Agreement and important transactional or relationship communications from American Express. American Express may also use the information obtained in the Merchant application at the time of setup to screen and/or monitor Merchant in connection with Card marketing and administrative purposes.
  3. Merchant may opt out of receiving future commercial marketing communications from American Express by contacting Processor (or Member Bank). However, Merchant may continue to receive marketing communication while American Express updates it records to reflect Merchant’s choice. Opting out of commercial marketing communications will not preclude Merchant from receiving important transactional or relationship messages from American Express.
  4. Merchant may be converted from the Program to a direct Card acceptance relationship with American Express if and when it becomes a High CV Merchant. Upon such conversion, Merchant will be bound by American Express’ then current Card Acceptance Agreement and American Express will set pricing and other fees payable by Merchant for Card acceptance.
  5. Merchant shall not assign to any third party any payments due to you under this the Program, and all indebtedness arising from Charges will be for bona fide goods and services (or both) at its Establishment(s) and shall be free of liens, claims, and encumbrances, other than ordinary sales tax. However, Merchant may sell and assign future transaction receivables to Processor (or Member Bank) or our affiliated entities and/or any other cash advance funding source that partners with Processor (or Member Bank) (or its affiliates) without the consent of American Express.
  6. American Express has the third party beneficiary rights, but not the obligations, to this Agreement, to fully enforce terms relating to the Program against Merchant.
  7. Merchant may opt out of accepting American Express Cards at any time without penalty and without directly or indirectly affecting your rights to accept Other Payment Products.
  8. Processor (or Member Bank) may immediately terminate Merchant’s right to accept American Express Cards or Merchant’s participation in the Program if: (i) Merchant breaches any provision of this Agreement related to the Program; (ii) upon request from American Express; (iii) Merchant engages in fraudulent or any other activity; or (iv) Merchant breaches any provision of the American Express Merchant Operating Guide.
  9. Merchant’s refund policies for purchases on the Card must be at least as favorable as its refund policies for purchases on any Other Payment Products, and the refund policy must be disclosed to the Cardmembers at the time of purchase and in compliance with Applicable Law. Merchant may not bill or collect from any Cardmember for any purchase or payment on the Card unless Chargeback has been exercised, Merchant has fully paid for the Charge, and Merchant otherwise has the right to do so.
  10. Merchants agrees to remove any American Express Licensed Marks from its website wherever else they are displayed upon termination of Merchant’s participation in the Program or termination of the Agreement.
  11. Merchant must comply with the American Express Data Security Requirements (DSR) and Payment Card Industry Data Security Standards (PCI DSS). In the event you become aware of any Data incident, Merchant must report such immediately to Processor (or Member Bank) after discovering of the incident.
  12. Merchant must ensure data quality and that Transaction Data and customer information is processed promptly, accurately and completely, and complies with the American Express Technical Specifications. Merchant is responsible for being aware of and adhering to privacy and data protection laws and provide specific and adequate disclosures to Cardmembers of collection, use, and processing of personal data.

Exhibit B: Data Protection

Exhibit B: Data Protection

1. Data Protection Service

If you elect the Data Protection Service, these terms and conditions shall apply.

DEFINITIONS: Capitalized terms used herein shall have the meanings given to such terms as set forth in this Addendum or as defined elsewhere in the Agreement.

Data Protection Service or Encryption and Tokenization means those services described below.

Multi-Pay Token means the option to support businesses that need to submit a financial transaction in a card-not-present situation. These tokens are unique to each merchant that uses them and are stored in place of the primary account number (PAN). With these tokens, merchants can initiate new or recurring payments in their own environment instead of using the original card number. Multi-Pay Token allows a Token Registration to process a non-financial transaction to request a token to be placed in their payment page or e-wallet for future or recurring payments. It is common for e-commerce merchants to ask their customers to register by providing profile information such as name, address, and phone number to the merchant website before or upon checkout.

Registered PAN means the processing of creating a Client Specific Token for a PAN.

Token/Tokenization means a form of data substitution replacing sensitive payment card values with non-sensitive token, or random-number, values. Post-authorization transactions are handled via Processors Safe Proxy tokenization technology, which returns a token with the transaction’s authorization to the merchant. Tokens are shared universally with other merchants and cannot be used to initiate a financial transaction.

Token Request means your ability to obtain a Multi PayToken for credit card information only without an immediate authorization required which permits you to store a Multi-Pay Token for future transactions involving its customer.

2. Grants of License

Subject to the terms of this Addendum, Processor grants to you a non-transferable, non-assignable, non-exclusive, revocable sub-license during the term of this Addendum to use the Data Protection Service and the Data Protection Service Marks (as identified in the Data Protection Rules and Procedures) in the United States in accordance with this Addendum, including without limitation the Data Protection Rules and Procedures. Any rights with respect to the Data Protection Service not expressly granted by Processor in this Addendum are deemed withheld.

3. Services

The Data Protection Service applies only to Card transactions sent from you to us for authorization and settlement pursuant to the Agreement, and specifically excludes electronic check transactions. Processor will provide an encryption key to you to be used to encrypt (make unreadable) Card data during transport of the authorization request from your point of sale to Processor’s systems. During the period when the transaction is being transmitted to Processor for authorization processing, all historical transaction data, including Card number and full magnetic stripe data (track data and expiration date), will be encrypted. Processor will then generate or retrieve a unique, randomly generated token assigned to the Card number that will be returned to you in the authorization response (the “Token”).

4. Responsibilities of Clients

You are responsible to comply with the following regarding your use of the Data Protection Service:

  1. You are required to comply with the Card Organization Rules, including taking all steps required to comply with the Payment Card Industry Data Security Standards (PCI DSS). You must ensure that all third parties and software used by you in connection with your payment processing are compliant with PCI DSS. Use of the Data Protection Service will not, on its own, cause you to be compliant or eliminate your obligations to comply with PCI DSS or any other Card Organization Rule. You must demonstrate and maintain your current PCI DSS compliance certification. Compliance must be validated either by a Qualified Security Assessor (QSA) with a corresponding Report on Compliance (ROC) or by successful completion of the applicable PCI DSS Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC), as applicable, and if applicable to your business, passing quarterly network scans performed by an Approved Scan Vendor, all in accordance with Card Organization Rules and PCI DSS.
  2. Use of the Data Protection Service is not a guarantee against an unauthorized breach of your point of sale systems or any facility where you process and/or store transaction data (collectively, “Merchant Systems”).
  3. You must deploy the Data Protection Service (including implementing any upgrades to such service within a commercially reasonable period of time after receipt of such upgrades) throughout your Merchant Systems including replacing existing Card numbers on your Merchant Systems with Tokens. Full Card numbers must never be retained, whether in electronic form or hard copy.
  4. You must use the Token in lieu of the Card number for ALL activities subsequent to receipt of the authorization response associated with the transaction, including, without limitation, settlement processing, retrieval processing, chargeback and adjustment processing, and transaction reviews.
  5. If you send or receive batch files containing completed Card transaction information to/from Processor, you must use the service provided by Processor to enable such files to contain only Tokens or truncated information.
  6. You must use truncated report viewing and data extract creation within reporting tools provided by Processor.
  7. You are required to follow rules or procedures we may provide to you from time to time related to your use of the Data Protection Service (“Data Protection Rules and Procedures”). We will provide you with advance written notice of any such rules or procedures or changes to such rules or procedures.
  8. You have no right, title, or interest in or to the Data Protection Service, any related software, materials or documentation, or any derivative works thereof, and nothing in this Addendum assigns or transfers any such right, title or interest to you. You shall not take any action inconsistent with the stated title and ownership in this Addendum. You will not file any action, in any forum, that challenges the ownership of the Data Protection Service, any related software, materials or documentation. Failure to comply with this provision will constitute a material breach of this Addendum. We have the right to immediately terminate this Addendum and your access to and use of the Data Protection Service in the event of a challenge by you. No additional rights are granted by implication, estoppel or otherwise.
  9. You will not: (1) distribute, lease, license, sublicense or otherwise disseminate the Data Protection Service or any portion of it to any third party; (2) modify, enhance, translate, supplement, create derivative works from, reverse engineer, decompile or otherwise reduce to human-readable form the Data Protection Service or any portion of it; (3) sell, license or otherwise distribute the Data Protection Service or any portion of it; (4) make any copies, or permit any copying, of the Data Protection Service or any portion of it as a standalone program or in any way independently from the Data Protection Service; or (5) use any portion of the Data Protection Service as a standalone program or in any way independently from the Data Protection Service. If any portion of the Data Protection Service contains any copyright notice or any other legend denoting the proprietary interest of Processor or any third party, you will not remove, alter, modify, relocate or erase such notice or legend on such item.
  10. You will only use the Data Protection Service for your internal business purposes in a manner consistent with this Addendum.
  11. You will use only unaltered version(s) of the Data Protection Service and will not use, operate or combine the Data Protection Service or any related software, materials or documentation, or any derivatives thereof with other products, materials or services in a manner inconsistent with the uses contemplated in this Addendum.
  12. You will promptly notify us of a breach of any terms of this Addendum.

5. Tokenization Limited Warranty

Processor warrants that the Token returned to you, as a result of using the Data Protection Service, cannot be used to initiate a financial sale transaction by an unauthorized entity/person outside the Merchant Systems. This warranty by Processor is referred to herein as the “Limited Warranty” and is subject to the terms and conditions set forth in this Addendum. To be eligible for the Limited Warranty, you must maintain a processing relationship with Processor and be in compliance with all the terms of the Agreement, including this Addendum, and any other agreement relating to Cards eligible for the Data Protection Service. Subject to the terms, conditions and limitations set forth in the Agreement, including the limitation of liability provisions, Processor agrees to indemnify and hold you harmless from direct damages, including third party claims, resulting from Processor’s breach of the Limited Warranty. The express remedy for Processor’s breach of the Limited Warranty set forth in this paragraph constitutes Processor’s entire liability and your sole and exclusive remedy for Processor’s breach of the Limited Warranty. The Limited Warranty is void if (i) you use the Data Protection Service in a manner not contemplated by, or in violation of, the Agreement, including this Addendum, or any other agreement relating to Cards eligible for the Data Protection Service; or (ii) you are grossly negligent or engage in intentional misconduct.

6. Data Protection Disclaimer

IN ADDITION TO THE DISCLAIMERS SET FORTH IN THE AGREEMENT, THE FOLLOWING DISCLAIMER APPLIES TO THE DATA PROTECTION SERVICE: EXCEPT AS EXPRESSLY PROVIDED IN THIS ADDENDUM, PROCESSOR MAKES NO REPRESENTATIONS, WARRANTIES OR COVENANTS, EXPRESS OR IMPLIED WITH REGARD TO THE DATA PROTECTION SERVICE INCLUDING THE UNINTERRUPTED OR ERROR-FREE OPERATION OF THE DATA PROTECTION SERVICE.

7. POS Software Monitor

A. Software as a Service: Subject to the terms and conditions of this Addendum, we agree to provide you with the POS Software Monitor software application, including all updates, upgrades, new versions, and other enhancements or improvements thereto (the “Software”), to the extent the applicable fees are paid. You hereby authorize us or our vendors to begin scanning immediately upon your installation and/or deployment of the Software. The Software can only be used with certain computer operating systems. It is your responsibility to ensure that your computer has the software in order to use the POS Software Monitor.

B. License Grant: Subject to the terms of this Addendum, we hereby grant to you a non-exclusive, non-transferable, non-assignable, revocable sub-license during the term of this Addendum to: (i) access and use the Software solely for the benefit of you and only for systems owned or licensed by you; (ii) access and use the Software solely for its intended use; and (iii) use all applicable end user documentation provided.

C. Revocation of License: Upon expiration or termination of the Agreement or this Addendum for any reason, your license shall automatically be revoked. Furthermore, your right to use or access the Software shall cease.

8. IP & Other Data Retrieval, Transmission and Scanning

A. IP/Data Retrieval and Transmission: You hereby grant us or our vendors the right to retrieve, transmit, and monitor, for the intended purpose of the POS Software Monitor, any dynamic or static IP address and other data, including without limitation policy and system settings, point of sale system type, version, security event logs, or other related information, from any system with the POS Software Monitor loaded, deployed, or otherwise installed. You shall not, in any event or in any manner, impede the retrieval or transmission of such IP addresses or data. You hereby assume full responsibility for all damages and losses, of any nature, for all adverse results caused by your impeding the retrieval and transmission of the IP addresses and data. You further agree to defend, indemnify, and hold us harmless from any third-party claim resulting from your impeding this process.

B. IP Scanning & Log Monitoring: You acknowledge and understand that provisioning of the Software will enable static or dynamic IP addresses associated with the POS Software Monitor to be scanned. You further acknowledge that such IP addresses may be for external network devices which protect the POS Software Monitor host system. You hereby grant us and our vendors: (i) the right to access and scan the IP addresses associated with the POS Software Monitor whether they are dynamic or static IP addresses (the “Authorized IP Addresses”); (ii) the right and authority to gather and transmit system data, including point of sale system information, to us or our vendors; and (iii) the right and authority to collect, transmit and review security event logs from the systems on which the Software is deployed. You further agree to provide us or our vendors reasonable assistance to enable such access and scanning. You understand that your failure to cooperate with the provision of services may significantly impair the services.

C. Updates: You acknowledge and understand that the POS Software Monitor, in our sole discretion, can automatically install, download, and/or deploy updated and/or new components (“update process”), which may include a new version of the POS Software Monitor itself. You shall not, in any event or in any manner, impede the update process. You hereby assume full responsibility for all damages and losses, of any nature, for all adverse results caused by your impeding the update process. You agree to defend, indemnify, and hold us harmless from any third-party claim resulting from your impeding the update process.

D. Authorized Disclosure: You acknowledge that, in conjunction with providing the Software, we may make certain “pass” or “fail” determinations regarding your online security and the vulnerability of your IP addresses. You hereby authorize us or our vendors to share these “pass/fail” results, point of sale data, and other information collected during the scans to Card Organizations, Payment Card Industry Security Standards Council, or any Card Organization sponsor bank.

9. PCI Rapid Comply Service

A. License Grant: Subject to the terms of this Addendum, we hereby grant to you a non-exclusive, non-transferable, non-assignable, revocable sub-license to: (i) access and use the PCI Rapid Comply Service solely for the benefit of you and only on a single computer or computer network owned or licensed by you; (ii) access and use the PCI Rapid Comply Service solely for its intended use; and (iii) use all applicable end-user documentation. Upon expiration or termination of the Agreement or this Addendum for any reason, your license shall automatically be revoked. Furthermore, your right to use or access the PCI Rapid Comply Service shall automatically be revoked. Furthermore, your right to use or access the PCI Rapid Comply Service shall cease.

B. Access: You acknowledge and agree that, although you will generally have access to the PCI Rapid Comply Service twenty-four hours per day, seven days per week (except in the event of a force majeure event), access to customer accounts and certain other services may not be available on a continuous basis and the PCI Rapid Comply Service will be subject to periodic downtime to permit, among other things, hardware and/or software maintenance to take place.

C. Data Disposal: From time to time, your account data or information, which is over 180 days old, may be deleted, purged, or otherwise disposed. In addition, only a limited amount of data or information may be available. Therefore, you are advised to print and download your account data and information, for record-keeping purposes, on a periodic basis. You specifically agree that we are authorized to delete or dispose of your data or information and shall not be responsible for the deletion or disposal of your data or information from the PCI Rapid Comply Service. You assume full responsibility to backup and/or otherwise protect your data against loss, damage, or destruction prior to and during all phases of the PCI Rapid Comply Service, and to take appropriate measures to respond to any potential adverse impact of the systems or disruption of service.

D. Copyrighted Material: The PCI Rapid Comply Service (including the website), contains copyrighted material, trademarks, and other proprietary information, including, but not limited to, text, software, photos, video, and you may not modify, publish, transmit, participate in the transfer or sale, create derivative works, or in any way exploit any of the content, in whole or in part, whether copyrighted, trademarked, or proprietary, or otherwise. You may download copyrighted material solely for your own internal use as contemplated under this Addendum. Except as expressly provided by copyright law, any copying, redistribution, or publication must be with the express permission of the owner. In any copying, the redistribution or publication of copyrighted material and any changes to or deletion of author attribution or copyright notice is expressly prohibited.

10. Liability Waiver

A. Data Security Event Expenses: Subject to the limitations, terms and conditions of this Section, we agree to waive liability (the “Liability Waiver”) that you have to us under the Agreement for Security Event Expenses and Post Event Services Expenses resulting from a Data Security Event first discovered by you or us while this Addendum is in effect. Except for the Liability Waiver for expenses as specifically set forth in this Addendum, (i) you remain responsible to perform all agreements and obligations under the Agreement and this Addendum including, without limitation, your obligation to comply with data security requirements; and (ii) we waive no rights or remedies under your Agreement including, without limitation, our right to terminate the Agreement in the event of a Data Security Event.

B. Maximum Waiver Amount:

  1. The maximum amount of liability that we shall waive under the Agreement for all Security Event Expenses and Post Event Services Expenses arising out of or relating to your Data Security Events first discovered during any Program Year regardless of the number of such Data Security Events is as follows:
    1. $100,000.00 maximum per each MID (merchant identification number) you have; and
    2. $500,000 aggregate maximum for all of your MIDs.
  2. The maximum amount of liability during any Program Year that we will waive:
    1. $10,000 maximum per each MID you have; and
    2. $25,000 aggregate maximum for all of your MIDs.

For avoidance of doubt, the limit set forth in this Section 10.B is part of and not in addition to the maximums set forth in Section 10.A.

11. Duties in the Event of Data Security Breach

A. You shall contact us immediately and, as directed by us, investigate, perform all remedial actions and cooperate fully with us, in the event of a Data Security Event. In all events, you shall not take any action, or fail to take any action, without our prior written consent, which prejudices our rights hereunder.

B. Under all circumstances, you shall not admit any liability, assume any financial obligation, pay any money, or incur any expense in connection with any Data Security Event without our prior written consent. If you do so, it will be at your own expense.

12. Exclusions

The Liability Waiver hereunder shall not apply to:

  1. Any Security Event Expenses and Post Event Services Expenses arising out of or resulting, directly or indirectly, from any dishonest, fraudulent, criminal, or malicious act, error, or omission, or any intentional or knowing violation of the law, if committed by you or your employees, officers, agents, or director;
  2. Any Security Event Expenses and Post Event Services Expenses arising out of or resulting from a claim, suit, action, or proceeding against you that is brought by or on behalf of any federal, state, or local government agency;
  3. Any Data Security Event relating to you which has experienced a prior Data Security Event unless you were later certified as PCI compliant by a qualified security assessor;
  4. Any Data Security Event arising out of your allowing any party (other than its employees or us) to hold or access Cardholder Information;
  5. Any Data Security Event if Client: (i) is categorized by any Card Organization as “Level 7” or (ii) processes more than six million (6,000,000) Card transactions during the twelve (12)-month period prior to the date this Addendum became effective;
  6. Any expenses, other than Security Event Expenses and Post Event Services Expenses, incurred by you arising out of or resulting, directly or indirectly, from a Data Security Event, including without limitation, expenses incurred to bring you into compliance with the PCI Data Security Standard or any similar security standard;
  7. Any Security Event Expenses, and Post Event Services Expenses arising out of or resulting, directly or indirectly, from physical injury, sickness, disease, disability, shock, or mental anguish sustained by any person, including without limitation, required care, loss of services, or death at any time resulting therefrom;
  8. Any Security Event Expenses, and Post Event Services Expenses arising out of or resulting, directly or indirectly, from any of the following:
  9. Any Security Event Expenses, and Post Event Services Expenses arising out of or resulting, directly or indirectly, from the presence of or the actual, alleged, or threatened discharge, dispersal, release, or escape of Pollutants, or any direction or request to test for, monitor, clean up, remove, contain, treat, detoxify, or neutralize pollutants, or in any way respond to or assess the effects of pollutants;
  10. Your failure to comply with this Addendum or the Agreement in connection with a Data Security Event;
  11. Any Data Security Event occurring before the effective date of this Addendum;
  12. Any expenses incurred for, or as a result of, regularly scheduled, recurring or routine security assessments, regulatory examinations, inquiries or compliance activities;
  13. Any fines or assessments levied against you that are not the direct result of a Data Security Event;
  14. Any Data Security Event arising out of any software not within your control; provided, however, this exclusion shall not apply to a Data Security Event arising out of a virus, Trojan horse or other software used by a third party to obtain fraudulent access to data to your computer system or to collect data in transit to or from your computer system; or
  15. Any Data Security Event arising out of a breach in a computer system in which you and other merchants, with no legal relationship to one another, have hosted accounts or share a common database, operating system or software applications.

13. Processor Technology and IP

All technology used by us or our licensors in connection with performing the Data Protection Services, including software, portals, data processing systems (each of the foregoing, in object code and source code form), report templates, documentation, and materials (collectively, “Processor Technology”), and any of our or our licensors' patents, trademarks, copyrights, trade secrets, and other intellectual property (“Processor IP”), and any derivative works of or modifications to the Processor Technology or Processor IP, is the sole and exclusive property of, and is valuable, confidential, and proprietary to, Processor or its licensors. Except as otherwise expressly provided herein, you shall not acquire any rights in any Processor Technology or IP as a result of receiving the Data Protection Services. You will not file any action, in any forum, that challenges the ownership of the Processor Technology or Processor IP. Failure to comply with this provision will constitute a material breach of this Addendum. We have the right to immediately terminate your access to and use of the Data Protection Services in the event of a challenge by you. No additional rights are granted by implication, estoppel, or otherwise.

14. Processor Technology and IP

In the course of providing the Data Protection Services, we may collect information relating to activities on your network (the “Data”), including, but not limited to, network configuration, TCP/IP packet headers and contents, log files, malicious codes, and Trojan horses. We retain the right to use the Data or aggregations thereof for any reasonable purpose.

15. Service Does Not Guarantee Compliance or Security

You acknowledge and agree that your use of the Data Protection Services does not guarantee your compliance with any of the rules or security standards established by the Card Organizations. You further acknowledge and agree that your use of the Data Protection Services does not guarantee the security of your IP addresses or that your systems are secure from unauthorized access. You are responsible for establishing and maintaining your own security policies and procedures, and for compliance with the Card Organization Rules and security standards, including any obligation to notify a Card Organization and/or us of any suspected breach of your systems or any suspicious transactions or fraudulent activity. You are responsible for any fines or penalties imposed by any Card Organization or any other expenses and liabilities pursuant to the Agreement less only the benefits to which you may be entitled under the Liability Waiver provisions of this Addendum. In the event of a suspected breach of your systems or any suspicious transactions or fraudulent activity, you authorize us to share the details of any questionnaire or compliance report with the Card Organizations, and grant us and our vendors the right to access and perform a scan of the IP addresses identified within your profile. You agree and authorize payment for the additional scan. You further agree to cooperate with an investigation into such matter to include complying with the Card Organization and us pursuant to the terms of the Agreement.

A. In addition to your obligations under the Agreement to comply with all laws, you are solely responsible for monitoring legal developments applicable to the operation of your business, interpreting applicable laws and regulations, determining the requirements for compliance with all applicable laws and regulations, and maintaining an ongoing compliance program.

16. Scanning Authority: Scanning Obligations

You represent and warrant that you have full right, power, and authority to consent for the Data Protection Services to scan for vulnerabilities the IP address and/or URL and/or domain names identified to us by you for scanning, whether electronically or by any other means, whether during initial enrollment or thereafter. If applicable, you shall obtain all consents and authorizations from any third parties necessary for us or our vendors to perform the Data Protection Services , including, without limitation, third party data centers, co-locations and hosts. We will not be required to execute agreements with any such third parties. You agree to defend, indemnify and hold us and our vendors harmless from any third-party claim that such access was not authorized. You may use the Data Protection Services and portals only to scan IP addresses, URLs and domain names owned by and registered to you. You understand that your failure to provide a complete list of and complete access to your IP addresses will significantly impair the scanning services and may result in incomplete or inaccurate results. You agree that all Data Protection Services hereunder, including without limitation their functionality and contents, is confidential information, and Client’s use and/or access to the Data Protection Services is subject to the terms of Confidentiality in the Agreement.

17. Scanning Risks

You acknowledge and understand that accessing, retrieving, transmitting, and scanning IP addresses and other data involves inherent risks, including, without limitation, risks related to system or network performance and availability, and data corruption. You assume full responsibility to backup and/or otherwise protect your data against loss, damage or destruction, and to take appropriate measures to respond to any potential adverse impact of the systems or disruption of service.

18. Use of Data Protection Services and Portals

Your use of our or our vendors’ services, portals, reports, and scanning solution is subject to the following restrictions: (i) Data Protection Services , portals, and reports may only be used for the stated purposes in this Addendum for your internal business purposes in accordance with all applicable laws (including any export control laws); (ii) Data Protection Services and portals utilized for scanning may only scan IP addresses, URLs and domain names owned by and registered to you; and (iii) you shall limit access to the portals to only those employees and/or contractors who have an obligation of confidentiality with you and only to those who have a requirement for such access on a “need to know” basis and you shall be solely responsible for disabling portals accounts for those employees and/or contractors who no longer require access. You shall promptly notify us of any unauthorized use of the Data Protection Services. You shall not: (i) decompile, reverse engineer, disassemble, or otherwise derive the source code from any component of the Data Protection Services or portals including the software embedded therein; (ii) modify, enhance, translate, alter, tamper with, upgrade or create derivative works of the portals, software or documentation; (iii) distribute, lease, license, sell, assign, sublicense or otherwise disseminate or transfer its rights to use any portion of the Data Protection Services to any third party; or (iv) strip out or alter any trademark, service mark, copyright, patent, trade secret, ownership or any other proprietary or Intellectual Property notices, legends, warnings, markings or indications on or within any component of the portals, software or documentation, or attempt (i), (ii), (iii) and/or (iv) above. You shall notify us immediately if you know, suspect or have reason to know that you or anyone you have granted access to the Data Protection Services violated any provision of this Addendum. Further you agree not to share your personal information (ODA, tax ID, MID, etc.) with a third party so they may gain access to the Data Protection Services.

19. Disclaimers

A. We do not make and hereby expressly disclaim all representations or warranties including, without limitation: (i) that access to the Data Protection Services will be uninterrupted or error-free; (ii) that security breaches will not occur with respect to any information communicated through the Data Protection Services, the Internet, or any common carrier communications facility; and (iii) as to the results that may or may not be obtained by you in connection with your use of the Data Protection Services. WE DO NOT MAKE ANY WARRANTY, GUARANTEE OR REPRESENTATION (EITHER EXPRESS OR IMPLIED) OF ANY KIND INCLUDING, WITHOUT LIMITATION, THE MERCHANTABILITY, TITLE, NONINFRINGEMENT OR FITNESS FOR A PARTICULAR PURPOSE OF ANY SERVICES PROVIDED UNDER THIS ADDENDUM, AND ALL SUCH WARRANTIES, GUARANTEES AND REPRESENTATIONS ARE HEREBY EXPRESSLY DISCLAIMED. ALL SERVICES PROVIDED UNDER THIS ADDENDUM ARE PROVIDED ON AN “AS IS, WITH ALL FAULTS.” USE OF THE SERVICES DOES NOT GUARANTY SECURITY OR PREVENT A SECURITY BREACH OR COMPROMISE. WE MAKE NO WARRANTIES, EITHER EXPRESSED OR IMPLIED THAT PARTICIPATION AND/OR USE OF OUR SERVICES WILL DETECT EVERY VULNERABILITY ON YOUR SYSTEM, IF ANY, OR THAT OUR VULNERABILITY ASSESSMENTS, SUGGESTED SOLUTIONS OR ADVICE WILL BE ERROR-FREE OR COMPLETE. CUSTOMER AGREES THAT WE SHALL NOT BE RESPONSIBLE OR LIABLE FOR THE ACCURACY OR USEFULNESS OF ANY INFORMATION PROVIDED BY US, OR FOR ANY USE OF SUCH INFORMATION.

B. You acknowledge and agree that we shall not be liable to you for any claims, damages, losses, obligations, costs or expenses or other liability arising directly or indirectly from or otherwise concerning: (i) any termination, suspension, delay or disruption of service (including billing for a service) by the Internet, any common carrier or any service provider; (ii) any failure, disruption or malfunction of any of the Data Protection Services, the Internet, or any communications network, facility or equipment beyond our or a third party’s reasonable control, whether or not attributable to one or more common carriers; (iii) your failed attempts to access the Data Protection Services or to complete transactions via any of the Data Protection Services; (iv) any failure to transmit, obtain or collect data or any machine or software errors or faulty or erroneous input by you; (v) any damages resulting from any delays and/or losses arising in connection with the Data Protection Services provided hereunder; or (vi) any loss of or inability to access data or information generated by Data Protection Services.

20. Limitation of Liability

Notwithstanding anything to the contrary in this Addendum or elsewhere, our cumulative liability to you for any claim related to this Addendum, and your use of the Services (whether arising from tort, statute, contract or otherwise) shall in all cases be limited to the actual, direct and proven out-of-pocket losses, damages or expenses suffered or incurred by you. Furthermore, our cumulative liability to you shall not, in any case, exceed the TransArmor Solution Fees paid to us by you during the twelve (12) month period immediately preceding the date the event giving rise to the claim occurred. Notwithstanding anything to the contrary in this Addendum or elsewhere, in no event shall we be liable to you or to any third party for any indirect, special, incidental, consequential, punitive or unproven losses, damages or expenses of any kind, including, without limitation, lost profits or loss of goodwill arising from the use or inability to use the Services including, without limitation, the inability to access your data or information generated or stored on the Services, and regardless of whether such claim arises in tort, in contract or by statute or regulation, each of which is hereby excluded, regardless of whether such damages were foreseeable or whether you have been advised of the possibility of such damages. The parties acknowledge and agree that the provisions and limitations of Section 22 are of the essence of this Addendum and that absent them, the parties would not have agreed to this Addendum.

21. Miscellaneous: Termination

Except as may be provided in the Agreement, a person who is not a party to this Addendum shall have no rights or remedies under this Addendum. Our obligations hereunder are subject to our ability to obtain and maintain any and all required governmental licenses, permits or other authorizations, and our ability to comply with any and all laws, regulations, orders and other governmental directives which may be imposed related to the Data Protection Services. We may terminate any or all of the Data Protection Services at any time for any reason.

Exhibit C: Additional Fee Schedules

Exhibit C: Additional Fee Schedules

Processor’s VAMP Threshold Fee Schedule

Merchant shall pay Processor’s VAMP-related costs and fees (including administrative, monitoring, remediation, and operational costs) in accordance with Processor’s VAMP Threshold Fee Schedule set forth below.

VAMP CategoryVAMP RatioMerchant Fee
Early Warning> 40 bps to < 50 bps
Greater than 0.40% and less than 0.50%
$0.00
Above Standard> 50 bps to < 70 bps
Greater than 0.50% and less than 0.70%
$10.00
Excessive> 70 bps to < 220 bps
Greater than 0.70% and less than 2.20%
$15.00
Unacceptable> 220 bps
Greater than 2.20%
$20.00

If Processor reasonably determines that Merchant’s activity is trending toward, approaching, or exceeding any VAMP metric or threshold, as defined by Visa, or any Processor VAMP Threshold, Merchant agrees to be automatically enrolled in Processor’s VAMP and TC40 reporting module and agrees to pay the following Reporting Module Fee.

Reporting Module Fee: $149 per month

Excessive Activity Fee Schedule

We reserve the right to assess additional processing fees for activities exceeding normal thresholds up to the amounts specified in the table below.

Excessive Activity Merchant Fee
Excessive ChargebacksAdditional $10.00 per chargeback when the total exceeds over 3% in chargebacks
Excessive Post Closure ChargebacksAdditional $15.00 per chargeback over 100 when the account has been closed
Excessive Prepaid CardsAdditional $0.25 per transaction when the total exceeds 1% in prepaid cards
Excessive DeclinesAdditional $0.25 per authorization when the total declines exceeds 40%
Excessive Rapid Dispute Resolution (RDR)Additional $10.00 per RDR when the total account exceeds over 3%

Chargeback Management Enrollment: We may, in our sole discretion, enroll Merchant in chargeback and dispute management programs offered by Verifi and/or Ethoca to help minimize disputes and consumer complaints. Unless otherwise agreed in writing, Merchant will be charged the then-current fee of $30.00 per alert (or any lower fee we make available).

Exhibit D: ACH Processing Addendum

Exhibit D: ACH Processing Addendum

This ACH Addendum forms part of, and is incorporated into, the Merchant Processing Agreement (“Agreement”), and is entered into by and among Processor, Merchant, and Member Bank, as identified on the Merchant application. Except as expressly modified by this ACH Addendum, the Agreement remains in full force and effect. Capitalized terms not defined in this ACH Addendum have the meanings given in the Agreement where specifically defined. If there is a conflict, this ACH Addendum controls solely with respect to the ACH Services.

For purposes of this Addendum, Bank and Processor may be collectively referred to hereinafter as the “Bank,” but if the obligations referenced herein are Processor’s obligations, the reference to Bank shall not broaden or expand Bank’s obligations hereunder. Subject to the requirements of applicable Nacha Rules, Processor and Bank may allocate their respective duties and obligations between themselves as they deem appropriate at their sole discretion, and Processor and Bank may jointly or individually assert or exercise their rights or remedies hereunder.

Recitals

Merchant wishes to initiate credit and/or debit Entries as an Originator through Bank, as an Originating Depository Financial Institution, to and from Merchant accounts maintained at Bank and at other depository financial institutions by means of the Automated Clearing House (“ACH”) (the “Services”). Bank is willing to act as an Originating Depository Financial Institution (“ODFI”), and Processor is willing to act as a Third-Party Service Provider (“TPSP”), with respect to such Entries, and Bank and Processor are willing to provide the Services subject to the terms of this Addendum.

Agreement

1. Definitions

Capitalized terms shall have the meanings set forth in the Nacha Rules except where otherwise specifically defined in this Addendum or in the Agreement.

2. General

Merchant agrees to use Services pursuant to the terms herein and in compliance with Applicable Law. In the event of inconsistency between a provision of Article 4A of the Uniform Commercial Code (the “UCC”) and this Addendum, the provisions of this Addendum shall prevail. Merchant agrees that its ability to originate Entries under this Addendum is subject to: (i) Bank’s approval, (ii) receipt by the Bank of all required and properly executed forms, authorizations, and such other information as Bank may reasonably request from time to time in connection with this Addendum, and (iii) Merchant’s compliance with the terms of this Addendum and all Applicable Laws. Merchant shall be responsible for all transactions initiated as an Originator and all Entries submitted to Bank.

3. Party Representations and Warranties

Merchant represents and warrants that: (i) Merchant has delivered complete and correct copies of all requested financial information and a complete, accurate, and correct application or information request. Merchant’s financial statements, subject to any limitation stated therein, which have been furnished to Bank, fairly represent the financial condition of Merchant; (ii) there is not pending or threatened against Merchant, any litigation or proceeding, judicial, tax or administrative, the outcome of which might materially adversely affect the continuing operations of Merchant; (iii) Merchant is in compliance with Applicable Law and has obtained and is in compliance with all licenses, permits, memberships, consents and authorizations required to perform all its obligations under this Addendum. With respect to each and every Entry transmitted to Bank under this Addendum, Merchant represents and warrants to Bank and agrees that (I) Merchant will be bound by and comply with the Nacha Rules as in effect from time to time; (II) each person or entity shown as the Receiver on an Entry received by Bank from Merchant has authorized the initiation of such Entry and the crediting or debiting of its account in the amount and on the Effective Entry Date shown on such Entry; (III) such authorization is operative at the time of transmittal for crediting or debiting by Bank as provided herein; and (IV) Entries transmitted to Bank are limited to those types of credit and debit Entries permitted in writing by Bank.

4. Authorization

Merchant authorizes Bank to originate Entries on behalf of Merchant to Receivers’ accounts. Merchant shall ensure only Authorized Users initiate debit or credit Entries hereunder. Merchant authorizes Processor, acting as a Third-Party Service Provider, to facilitate the preparation, transmission, and delivery of Entries and related information to Bank on Merchant’s behalf.

  1. Evidence of Authorization. Merchant will obtain all consents and authorizations for all Entries. Such authorizations and any related disclosures shall comply with (i) all requirements of the Nacha Rules and (ii) all Applicable Law, including, without limitation, any applicable requirements of Regulation E, the Federal Electronic Funds Transfer Act, and sanctions enforced by OFAC. Merchant shall ensure each Entry is and will be made according to such authorization and shall comply with the Nacha Rules. Merchant will not initiate any Entry after such authorization has been revoked or the arrangement between a customer and Receiver or other party has terminated. Merchant shall retain all consents and authorizations for the period required by the Nacha Rules. Merchant will, within one (1) Business Day of Bank’s or Furnisher’s request, furnish to Receiver or to Bank an original or a copy of any transaction authorization requested by Receiver or Bank. No investigation or verification procedure undertaken by Bank shall be deemed to limit or waive Merchant’s obligations under this Addendum.

5. Financial Statements and ACH Limits

Merchant agrees that: (i) the Services and this Addendum are subject to the Bank’s assessment and approval of its settlement risk, (ii) that in order to evaluate such risk and for underwriting purposes certain documentation is required from the Merchant from time to time, and (iii) the Bank shall have the right to reject the application of Merchant for the Services or continuation of such Services if, in the Bank’s judgment, the information provided by Merchant is not deemed satisfactory including, without limitation, for purposes of the Bank’s evaluation of its settlement risk. Merchant must submit, upon Bank’s request, audited and unaudited financial statements in the form and manner required by Bank. Bank shall also be authorized to obtain a credit report(s) on Merchant as may be necessary from time to time. Bank may also assign Merchant a limit representing the maximum aggregate dollar amount of Entries (including a maximum amount for each SEC Code), as well as In-Process Entries, which may be initiated by Merchant each day, month and/or year (this and any other transaction or Entry limit contemplated by this Addendum, an “ACH Exposure Limit”). Merchant shall not submit to Bank any Overlimit Entry; provided, however, if Bank receives any Entry from Merchant that would be considered an Overlimit Entry or that would otherwise cause Merchant to exceed the ACH Exposure Limit, Bank may, at its sole discretion, honor or reject such Entry. In addition to the limitations set forth herein, Bank may place additional limits on the amount or the type of Entries that Merchant may originate or submit in a file, batch or any single Entry. Bank will communicate any limit to Merchant from time to time and Merchant hereby agrees to ensure that all Entries originated by Merchant comply with such limit. Bank may, in its sole discretion, determine to reject any Entry or file that exceeds the ACH Exposure Limit, that Bank reasonably suspects is fraudulent or unauthorized or for any other reason provided for under the terms of this Addendum. Bank reserves the right to modify each ACH Exposure Limit from time to time at its sole discretion.

6. Designation of Representative

In order to originate or submit Entries, Bank may require Merchant to designate an authorized user (each such designated person, an “Authorized User”). Authorized User(s) shall be responsible for designating other users who Merchant authorizes to issue Entries on its behalf (each to be considered an Authorized User). Bank shall be entitled to rely on the designations made by the Merchant’s Authorized User(s) and shall not be responsible for matching the names of the Authorized User to names or titles listed in Merchant’s banking resolutions. Merchant agrees that any Entries transmitted shall comply with the Security Procedures, which are subject to change without notice to Merchant.

7. Merchant’s Obligations

In addition to such other duties and obligations as are set forth in this Addendum, the Merchant also agrees to the following:

  1. Merchant Compliance with Law and Policies. At all times, Merchant, in performing its duties and obligations under this Addendum, whether or not an Entry is sent through the ACH network, shall comply with and be bound by all Applicable Law, including, but not limited to, Nacha Rules and shall ensure that each Entry originated or submitted complies with Applicable Law, including but not limited to sanctions enforced by OFAC (including obtaining information regarding such OFAC enforced sanctions) and any Bank policies provided to Merchant. Merchant acknowledges it has a copy or has access to a copy of the current Nacha Rules, which may also be purchased online at www.nacha.org. Merchant agrees that the performance of any action by Bank hereunder, including debiting or crediting an account or transfer funds otherwise, is excused from the performance of such action to the extent that the performance is inconsistent with Applicable Law. Merchant agrees and warrants to Bank that all actions of Merchant and its Third-Party Service Providers, including the preparation, transmittal, and settlement of Entries and payment orders, shall comply in all respects with Applicable Law and this Addendum. Bank will charge Merchant with any fines or penalties imposed by any Regulatory Authority or any organization which are incurred as a result of the actions or omissions of the Merchant, Receiver or Third-Party Service Provider, and Merchant agrees to fully reimburse and/or indemnify Bank for such charges or fines assessed against or incurred by the Bank. The specific duties of Merchant provided in this Addendum in no way limit the foregoing undertaking. Bank reserves the right to suspend Merchant (or any Third-Party Service Provider) for breach of the Nacha Rules or to terminate this Addendum for any violation of Applicable Law. Bank reserves the right to audit Merchant (or any Third-Party Service Provider’s) compliance with this Addendum and with the Nacha Rules.
  2. Audits. Merchant hereby grants to Bank and Processor and/or their respective auditors the right of access to Merchant’s books and records and agrees to provide assistance at all times during the term of the Addendum for the purposes of allowing Bank and Processor and/or auditors to conduct an audit and/or verify Merchant’s compliance with this Addendum and the Nacha Rules. Merchant acknowledges that Bank and Processor have the right to periodically review the volume and character of Merchant’s ACH transactions and its business operations to evaluate the risk associated with providing the ACH Services.
  3. Fraud and Risk Management System. Merchant shall establish and implement risk-based processes and procedures, relevant to the role it plays in the authorization or Transmission of Entries, that are reasonably intended to identify Entries that are suspected of being unauthorized or authorized under False Pretenses (the “Risk Management System”). Merchant shall at least annually review these processes and procedures and make appropriate updates to address evolving risks.
  4. Personal Guaranties. In order to reduce the risk of loss to which Bank is subject under this Addendum, Bank may, in its sole discretion, require personal guaranties of Merchant’s principals. Merchant agrees that it will supply Bank with information it reasonably may request concerning its principals, including, but not limited to securing its principals’ authorizations to obtain credit reports or other information regarding such principal’s creditworthiness.
  5. Disputes with Receivers. Merchant is solely responsible to settle any disputes between Merchant and its Receivers. Merchant agrees that Processor and Bank will have no responsibility in resolving or settling such disputes.

8. Origination Services

  1. Transmittal of Entries by Merchant. Merchant authorizes Bank to originate the types of Entries submitted to it, and Merchant shall ensure such Entries meet the requirements of this Addendum and Bank’s instructions and comply with the formatting and other requirements set forth in the Nacha Rules, this Addendum and any other documentation provided to Merchant by Bank. Only an Authorized User may initiate debit or credit Entries hereunder on behalf of Merchant; provided, Bank shall be entitled to deem any person having knowledge of any Security Procedure, to be an Authorized User. Merchant or Authorized User(s) shall transmit or deliver Entries to Bank in computer readable form to the location(s) specified by Bank. Entries shall be transmitted to Bank’s designated location not later than the time and the number of days prior to the Effective Date (as defined by the Nacha Rules) specified by Bank (it being understood that, absent any written instructions from Bank, Merchant shall transmit such Entries in a timely manner to allow Bank a reasonable period to process such Entries prior to the Effective Date). Entries received after the cut-off time shall be deemed to have been received on the next Business Day. The total dollar amount of Entries transmitted by Merchant to Bank on any day shall not exceed the limit set forth in ACH Exposure Limit, unless otherwise approved by Bank in writing. Merchant shall ensure Entries submitted to Bank comply with Applicable Law. Prior to such Entry submission, Merchant shall ensure all debit or credit authorizations have been obtained as required by the Nacha Rules and Applicable Law. Merchant shall retain proof of these authorizations as required by the Nacha Rules and Applicable Law.
  2. Restrictions on Entries. Merchant may originate only those types of Entries, including only those SEC Codes and debit or credit transaction types, that Bank permits from time to time under this Addendum, Bank’s ACH guidelines, or other written instructions provided or made available to Merchant. If Bank authorizes Merchant to submit to Bank, or if Merchant processes using the Services, or otherwise originates any SEC Code Entry, Merchant (i) hereby makes all representations and warranties set forth in the Nacha Rules for each such SEC Code, and (ii) will take all such actions and obtain all consents and authorizations required under the Nacha Rules that would allow Bank to meet its obligations as ODFI of such Entries. Bank may restrict, condition, suspend, or prohibit Merchant’s origination of any Entry type or SEC Code at any time in accordance with the Nacha Rules, Applicable Law, or Bank policies. Merchant shall not originate any Entry type or SEC Code unless authorized by Bank to do so. Bank reserves the right to reject any Entry or group of Entries that are not authorized by Bank.
  3. Processing, Transmittal and Settlement by Bank. Except for On-Us Entries and rejected Entries, Bank shall (i) process Entries received from Merchant to conform with the file specifications set forth in the Nacha Rules; (ii) transmit such Entries as an ODFI to the ACH Operator by the deposit deadline of the ACH Operator (provided such Entries: (a) are completely received by Bank prior to the Bank’s cut-off time at the location specified by Bank; (b) the Effective Entry Date satisfies the criteria provided by Bank to Merchant; and (c) the ACH Operator is open for business on such day and such day is a Business Day); and (d) settle for such Entries as provided in the Nacha Rules. If such requirements are not met, Bank shall use reasonable efforts to transmit such Entries to the ACH Operator by the next deadline of the ACH Operator. Merchant will hold Bank harmless from all fees and expenses that may be incurred by Bank as a result of delivery of any late Entry.
  4. On-Us Entries. Except for rejected Entries, in the case of an Entry received for credit or debit to an account maintained with Bank (“On-Us Entry”), Bank shall credit the Receiver’s account in the amount of such Entry on the Effective Entry Date contained in such Entry or the deadline specified in Bank’s written ACH guidelines, whichever is later, provided the requirements set forth in this Addendum are met. If the requirements are not met, Bank will use reasonable efforts to credit or debit the Receiver’s account in the amount of such Entry no later than the next Business Day following the Effective Entry Date.
  5. Rejection of Entries. Bank may reject any Entry (i) if the Merchant and/or Entry does not adhere to or comply with this Addendum, Bank’s ACH guidelines, Applicable Law or applicable Security Procedures; (ii) that contains an effective Entry Date more than two (2) Business Days after the Business Day such Entry is received by Bank (or any other applicable period determined by Bank and communicated to Merchant); (iii) for any reason for which an Entry may be returned under the Nacha Rules; or (iv) if Merchant has failed to comply with any account balance or prefunding obligations under this Addendum. Bank may (but is not obligated to) notify Merchant by email or electronic transmission of such rejection no later than the Business Day such Entry would otherwise have been transmitted by Bank to the ACH Operator or, in the case of an On-Us entry, its Effective Entry Date. Any notice of a rejected Entry will be effective when given; provided, however, Bank shall have no liability to Merchant by reason of the rejection of any such Entry or the fact that such notices are not given. In the event that any Entries are rejected by the ACH Operator for any reason, it shall be the responsibility of Merchant to remake such Entries.
  6. Cancellation or Amendment by Merchant. Merchant shall have no right to cancel or amend any Entry after its receipt by Bank. However, if a Merchant request for cancellation or amendment complies with the procedures for canceling or amending Entry Data, Bank shall use reasonable efforts to act upon such a request by Merchant prior to transmitting the Entry to the ACH Operator or, in the case of an On-Us Entry, prior to crediting or debiting a Receiver’s account, but shall have no liability if such cancellation or amendment is not effected. Merchant shall reimburse Bank for any expenses, losses or damages Bank may incur in effecting or attempting to effect Merchant’s request for the cancellation or amendment of an Entry.
  7. Reversals of Entries or Files. Merchant must make a reasonable attempt to notify the Receiver of any Reversing Entry initiated to correct any Entry it has initiated in error. The notification to the Receiver must include the reason for the reversal and be made no later than the Settlement Date of the reversing Entry.
  8. Account Reporting and Error Detection. Merchant will promptly review each periodic statement, invoice, notice, and any other information concerning Merchant’s use of the ACH Services upon its receipt. Merchant agrees to notify Bank and Processor of any alleged error or discrepancy, including any unauthorized or erroneous Entries, within a reasonable time, not exceeding thirty (30) days from the date that the periodic statement or other notice is made available to Merchant. Merchant’s failure to report any error or discrepancy to Bank and Processor within thirty (30) calendar days of the information becoming available to Merchant will be deemed a waiver of any right to amounts that may be owed to Merchant in connection with such error or discrepancy. MERCHANT ACKNOWLEDGES AND AGREES THAT PROCESSOR AND BANK SHALL NOT BE LIABLE OR OTHERWISE RESPONSIBLE TO MERCHANT, AND SHALL HAVE NO OBLIGATION TO REIMBURSE MERCHANT, FOR ANY UNDERPAYMENT TO MERCHANT OR OTHER DISCREPANCY THAT IS NOT REPORTED TO PROCESSOR AND BANK IN WRITING WITHIN THIRTY (30) DAYS OF MERCHANT’S RECEIPT OF THE APPLICABLE STATEMENT. Merchant acknowledges and agrees that Bank has no obligation to discover and shall not be liable to Merchant for errors made by Merchant or any other Person, including errors made in identifying the Receiver, or an Intermediary or RDFI, or for errors in the amount of an Entry, or for errors in Settlement Dates. Bank shall likewise have no duty to discover and shall not be liable for duplicate Entries issued by Merchant. In the event that Merchant makes an error or issues a duplicate Entry, Merchant shall reimburse Bank for any loss, damages, or expenses incurred by Bank as result of the error or issuance of duplicate Entries.
  9. Prohibited Transactions. Merchant shall not use or attempt to use the Services (i) to engage in any illegal purpose or activity or to violate any Applicable Law; (ii) to engage in any internet or online gambling transaction, whether or not gambling is legal in any applicable jurisdiction, unless approved by Bank in writing and subject to any instructions provided to Merchant by Bank; or (iii) to engage in any transaction or activity that is specifically prohibited by this Addendum or Bank’s ACH guidelines. Merchant shall not initiate any IAT Entries without first receiving Bank’s prior written approval. Merchant acknowledges and agrees that Bank has no obligation to monitor Merchant’s use of the Services for transactions and activity that is impermissible or prohibited under the terms of this Addendum. Notwithstanding, Bank may decline to execute any transaction or activity that Bank believes violates the terms of this Addendum.
  10. Notice of Returned Entries. Bank shall notify Merchant by email or online notification of the receipt of a returned Entry from the ACH Operator as soon as is reasonably practicable under the circumstances, or no later than one (1) Business day after the day of such receipt. Bank shall have no obligation to retransmit a returned Entry to the ACH Operator if Bank complied in all material respects with the terms of this Addendum in connection with the original Entry. Merchant is solely responsible for any and all returned or rejected items, including any fees that may apply. Merchant authorizes Processor and Bank to deduct the amount of any returned or rejected item from the balance of funds currently due to Merchant.
  11. Notifications of Change. Bank will provide Merchant all information, as required by the Nacha Rules, with respect to each Notification of Change (“NOC”) Entry or Corrected Notification of Change (“Corrected NOC”) Entry received by Bank relating to Entries transmitted by Merchant. Bank shall provide such information to Merchant within two (2) banking days of the Settlement Date of each NOC or Corrected NOC Entry. Merchant shall ensure that changes requested by the NOC or Corrected NOC are promptly made within six (6) banking days or prior to initiating another entry to the Receiver’s account, whichever is later.
  12. Prenotification. Merchant, at its option, may send prenotification that it intends to initiate an Entry or Entries to a particular account within the time limits prescribed for such notice in the Nacha Rules. Such notice shall be provided to Bank in the format and on the medium approved by Bank and in compliance with the Nacha Rules. If Merchant receives notice that such prenotification has been rejected by an RDFI within the prescribed period, or that an RDFI will not receive Entries without having first received a copy of an authorization signed by its customer, Merchant will not initiate any corresponding Entries to such accounts until the cause for rejection has been corrected or until providing the RDFI with such authorization within the time limits provided by the Nacha Rules.
  13. Return Rates in Excess of Thresholds. In the event the rate of unauthorized returns of Entries, administrative returns of Entries or overall rates of returns submitted by Merchant exceeds the threshold rates identified in Bank’s ACH guidelines or Nacha Rules, Bank will share the data with Merchant and Merchant will take immediate steps to revisit its authorization procedures to reduce the unauthorized return rates, administrative return rates or overall rates below the threshold rate and shall further promptly prepare and submit a written plan and timeline to Bank noting Merchant’s intended plan to reduce unauthorized returns, administrative returns or its overall return rates. Bank will provide reporting information to Nacha regarding Merchant if Merchant’s return rate for unauthorized Entries exceeds the Unauthorized Entry Return Rate Threshold, the Administrative Return Rate Level or Overall Return Rate Level as required by the Nacha Rules.
  14. Debit Entries; Holds; Setoff; Reserve Account. Bank may establish or require a holding account, Reserve Account, or similar account to cover returned or rejected Debit Entries originated by Merchant or other amounts otherwise payable in connection with the ACH Services. If Bank makes funds from a Debit Entry available to Merchant and the Debit Entry is later rejected or returned, Merchant shall promptly reimburse Bank in immediately available funds for the amount of the rejected or returned Debit Entry, except to the extent Bank recovers such amount from any applicable Reserve or holding account. Bank may, in its discretion, hold, delay, net, offset, or apply any funds, settlement amounts, reserve amounts, or other amounts otherwise payable in connection with the ACH Services to address actual or anticipated returns, reversals, adjustments, disputes, fees, losses, or other obligations arising under this Addendum. Merchant is responsible for all Entries submitted or processed under this Addendum, including any Debit Entry that is returned, rejected, reversed, disputed, or otherwise not finally settled after funds have been made available. If Bank determines that available funds or reserves are insufficient, Merchant will promptly provide immediately available funds in the amount required by Bank. Bank’s exercise or non-exercise of any hold, reserve, offset, debit, or other risk-control measure will not limit Merchant’s or Processor’s obligations under this Addendum.
  15. Payment for Credit Entries and Returned Debit Entries. Merchant agrees to pay Bank for all credit Entries submitted, processed or issued by Merchant or Authorized User(s) or credit Entries otherwise made effective against Merchant. Merchant shall make payment at such time on the date of transmittal by Bank of such credit Entries as Bank, in its discretion, may determine (“Payment Date”), and the amount of each On-Us Entry at such time on the Effective Entry Date of such credit Entry as Bank, in its discretion, may determine. Merchant shall pay Bank for the amount of each debit Entry returned by an RDFI or debit Entry dishonored by Bank. Merchant shall make payment to Bank in any manner specified by Bank.

    Notwithstanding the foregoing, Bank is hereby authorized to charge Merchant’s Designated Account, Reserve Account, holding account, or any other Merchant-designated account as payment for credit Entries issued by Merchant or returned or dishonored debit Entries. In the event such accounts do not have sufficient available funds on the Payment Date, Bank is hereby authorized to charge any account maintained by Merchant with Bank or any other Merchant-designated account as payment for credit Entries issued by Merchant or returned or dishonored debit Entries. Merchant shall maintain sufficient collected funds in Merchant’s account(s) to settle for the credit Entries on the Payment Date. In the event that no Merchant account has collected funds sufficient on the Payment Date to cover the total amount of all Entries to be paid on such Payment Date, Bank may take any of the following actions: (i) refuse to process all Entries, or (ii) process all credit Entries. In the event Bank elects to process credit Entries initiated by Merchant, the total amount of the insufficiency advanced by Bank on behalf of Merchant shall be immediately due and payable by Merchant to Bank without any further demand from Bank.

  16. Prefunding. Bank reserves the right to require Merchant to pre-fund an account maintained at Bank prior to the Settlement Date of the ACH file. Bank shall determine whether pre-funding is required based on criteria established from time to time by Bank. Bank will communicate directly to Merchant if pre-funding is required and, if requested by Merchant, will provide Merchant with an explanation of its pre-funding criteria. If it is determined that pre-funding is required, Merchant will provide immediately available and collected funds sufficient to pay all Entries initiated by Merchant (a) not later than the time instructed by Bank or set forth in the ACH guidelines, whichever is earlier, and (b) prior to initiating any Entries for which pre-funding is required.
  17. Provisional Settlement. Merchant acknowledges and agrees that a payment made by an RDFI to a Receiver is provisional until receipt by the RDFI of final settlement for such Entry and, if such settlement is not received, the RDFI shall be entitled to a refund from the Receiver of the amount credited and Merchant shall not be deemed to have paid the Receiver the amount of the Entry.
  18. Inconsistency of Name and Account Number. The Merchant acknowledges and agrees that, if an Entry describes the Receiver inconsistently by name and account number, payment of the Entry transmitted by Bank to the RDFI may be made by the RDFI (or by Bank in the case of an On-Us Entry) on the basis of the account number supplied by the Merchant, even if it identifies a person different from the named Receiver, and that the Merchant’s obligation to pay the amount of the Entry to Bank is not excused in such circumstances. Similarly, if an Entry describes an RDFI inconsistently by name and routing number, payment of such Entry may be made based on the routing number, and Merchant shall be liable to pay the amount of that Entry to Bank. Merchant is liable for and must settle with Bank for any Entry initiated by Merchant that identifies the Receiver by account or identifying number or by name and account or identifying number.
  19. Records. Merchant shall retain all records, authorizations, consents, source documents, transaction data, and other information required to demonstrate compliance with this Addendum, the Nacha Rules, and Applicable Law for the period required by the Nacha Rules and Applicable Law. Merchant shall provide such records and information to Bank or Processor upon request. Merchant shall also retain, for a commercially reasonable period after transmittal, sufficient Entry data to permit Bank or Processor to investigate, correct, or remake Entries.
  20. Additional Limits. Merchant agrees that Bank will not process an Overlimit Entry. Bank will suspend any Overlimit Entry submitted by Merchant and may, following its receipt of an Overlimit Entry, suspend all In-Process Entries. Merchant acknowledges that any Overlimit Entry or other In-Process Entries suspended by Bank will not settle on their scheduled Settlement Date. If Merchant wishes to initiate an Entry that would cause the amount of In-Process Entries to exceed the ACH Exposure Limit, Merchant may submit to Bank its request to initiate an Entry that otherwise would be an Overlimit Entry. Bank may grant or deny Merchant’s request at its sole discretion. In addition to the foregoing, Bank generally reserves the right to limit the nature and amount of the preauthorized debit/credit Entries processed under this Addendum or to refuse to process any debit/credit Entries under this Addendum if, in Bank’s sole judgment (i) there is reasonable cause to believe that any Entry will be returned or will not settle in the ordinary course of the transaction for any reason, (ii) to do otherwise would violate any limit set by the applicable clearing house association or any governmental authority or agency to control payment system risk, or (iii) a preauthorized credit Entry or the return of a preauthorized debit Entry would create an overdraft of Merchant’s account(s). Bank may limit the transactions initiated by Merchant to specific SEC Codes. Merchant may not reinitiate entries except as prescribed by the Nacha Rules. MERCHANT HEREBY INDEMNIFIES AND HOLDS HARMLESS THE BANK FOR ANY LOSSES, DAMAGES, FINES, ASSESSMENTS, COSTS AND EXPENSES INCURRED BY BANK ARISING FROM ANY SUSPENDED OR UNPROCESSED OVERLIMIT ENTRIES OR ANY IN-PROCESS ENTRIES THAT MAY BE SUSPENDED PURSUANT TO THIS SECTION.
  21. Merchant as Receiver. If Merchant is the Receiver of an Entry or other funds transfer, and Bank does not receive final settlement for any payment made to Merchant by the Receiving Depository Financial Institution, Merchant acknowledges and agrees that Merchant is obligated to Bank for the amount of the payment order and Bank is authorized to charge Merchant’s account(s) held at Bank or otherwise designated by Merchant for any amount paid to Merchant. If Bank credits Merchant’s account for an Entry or other funds transfer naming Merchant as the Receiver, such credit Entry to Merchant’s account is not acceptance of the funds transfer by Bank until at least after the opening of business on the banking day after the credit Entry is made to the account. Notwithstanding the foregoing, Bank may make funds available to the Merchant at an earlier time at Bank’s option. Bank has no obligation to notify Merchant of receipt of a funds transfer naming Merchant as the Receiver even if payment for the funds transfer to Merchant is made by credit to Merchant’s account or the payment order directs payment to an account.
  22. Third-Party Senders and Nested Third-Party Senders. Merchant is prohibited from operating as a Third-Party Sender or entering into an ACH origination agreement with any Third-Party Sender or a “nested” Third-Party Sender in connection with this Addendum. The Nacha Rules contain special requirements and impose additional obligations on Bank when it acts as Merchant’s ODFI with respect to Entries Merchant sends as a Third-Party Sender. Subject to Bank’s prior approval and in its sole discretion, Merchant may elect to process Entries on behalf of its clients, who may or may not be Bank customers (defined as a “Third-Party Sender” and/or “Nested Third-Party Senders” under the Nacha Rules), as well as on Merchant’s own behalf. Merchant shall execute any such other agreement(s) or documents as Bank deems necessary or appropriate prior to the initiation or continuation by Merchant of any ACH services in the capacity of a Third-Party Sender or in connection with any Nested Third-Party Sender. Merchant agrees that Bank retains the right to reject any request by Merchant to engage in Third-Party Sender and/or Nested Third-Party Sender activities as well as any Entries initiated by Merchant in such a Third-Party Sender capacity or in connection in this capacity with any Nested Third-Party Sender, in Bank’s sole discretion.

9. Security Procedures

  1. Security Procedures. Merchant shall comply with the Security Procedures herein or as established by Bank from time to time with respect to Entries transmitted by Merchant to Bank or Processor (collectively, the “Security Procedures”). Merchant acknowledges and agrees that the Security Procedures, including (without limitation) any code, password, personal identification number, user identification technology, token, certificate, or other element, means, or method of authentication or identification used in connection with a Security Procedure (“Security Devices”) used in connection therewith, constitute commercially reasonable security procedures as defined by UCC § 4A-103 or under Applicable Law for the origination of Entries (or request for cancellation or amendment of an Entry).
  2. Purpose; No Error Detection. Merchant acknowledges that the purpose of such Security Procedures is for verification of authenticity and not to detect an error in the transmission or content of an Entry. No Security Procedures for the detection of any such error has been agreed upon between Processor or Bank and Merchant.
  3. Authorized Users and Safeguards. Merchant shall establish, maintain, and follow commercially reasonable administrative, technical, and physical safeguards to protect against unauthorized transmissions and unauthorized access to or use of the ACH services. Merchant shall permit only authorized personnel to initiate Entries or related instructions, shall maintain appropriate supervision and internal controls over such personnel, and shall promptly revoke access for any person who is no longer authorized. Merchant shall take reasonable steps to maintain the confidentiality of the security procedures and any passwords, codes, security devices and related instructions provided by Processor or Bank in connection with the Security Procedures. Merchant shall immediately notify Bank if Merchant knows or suspects that any Security Procedure, credential, authentication method, system, Entry data, or Protected Information has been lost, stolen, compromised, accessed by an unauthorized person, or otherwise used or disclosed in an unauthorized manner. Bank shall have a reasonable time to act on any such notice.
  4. Authenticated Instructions. Bank may act on any Entry or related instruction that Bank receives in Merchant’s name in compliance with the Security Procedures, whether or not the Entry or instruction was actually authorized by Merchant. Merchant shall be bound by each such Entry or instruction to the fullest extent permitted by Applicable Law and the Nacha Rules. Merchant further acknowledges and agrees that Merchant bears the sole responsibility for detecting and preventing errors in the Entries submitted to Bank, including errors that are the result of security breaches, fraud, or other malicious acts against Merchant by third parties.
  5. Protection of ACH Data. Merchant shall implement and maintain security policies, procedures, and systems designed to protect the confidentiality and integrity of Entries, Entry data, authorizations, Receiver information, DFI account numbers, routing numbers, and other Protected Information, and to protect against anticipated threats, unauthorized access, and unauthorized use. Merchant shall not disclose, sell, purchase, provide, or exchange Protected Information except as permitted by the Nacha Rules and Applicable Law. To the extent required by the Nacha Rules, Merchant shall render DFI account numbers unreadable when stored electronically, including through encryption, tokenization, truncation, secure hosted storage, or another commercially reasonable method.
  6. Breach Notification. Merchant will immediately notify Bank and Processor (and in all cases within 48 hours) if Merchant becomes aware of any actual or suspected compromise in the security, confidentiality, or integrity of any Protected Information, or information systems in the possession or control of Merchant or any of Merchant’s affiliate(s), contractor(s), or agent(s), regardless of cause (a “Data Breach”), including but not limited to any actual or suspected third-party intrusion into any such information system, and any failure, malfunction, inadequacy, or error of any hardware, software, or system, wherever located, on or through which Merchant Data or Protected Information resides, passes, or is accessed. Merchant understands that failure to comply with Security Procedures or a Data Breach may result in assessments, fines, or penalties by Nacha or a Regulatory Authority. Merchant agrees it is liable for, and will indemnify and reimburse Bank and Processor for, any such assessment, fine, or penalty imposed on Bank or Processor, as well as for any related losses, costs, or other expenses incurred by them in connection with a Data Breach.
  7. Transmission Over Unsecured Networks. Merchant shall not transmit Entries, banking information, DFI account numbers, routing numbers, authorizations, or other Protected Information over an Unsecured Electronic Network unless the information is encrypted or transmitted through a secure session using a commercially reasonable level of security.
  8. Changes to Security Procedures. Bank reserves the right to change, amend, replace, or cancel any or all Security Procedures, at any time and from time to time at Bank’s discretion. Bank may make any change in Security Procedures without advance notice to Merchant if Bank, in its sole discretion, believes such change to be necessary or desirable to protect the security of Bank’s systems. Merchant’s continued use of the ACH services after Bank makes changed Security Procedures available or requires their use constitutes Merchant’s agreement to such changed Security Procedures and Merchant’s acknowledgment that such changed Security Procedures are commercially reasonable and adequate for the purposes intended.

10. Compensation and Fees

Merchant agrees to compensate Bank and Processor for the ACH Services provided pursuant to this Addendum in accordance with the applicable fee schedules, Merchant application, or other agreement(s) between or among Merchant, Bank, and Processor, as in effect from time to time, that apply to the Services. Merchant authorizes Bank and Processor to charge Merchant’s Designated Account for the fees to the extent such fees are not offset against credits, settlement funds, reserves, or other amounts otherwise payable to Merchant. If the balance of available funds in Merchant’s Designated Account is not sufficient to cover such fees, Bank may charge the fees to any other Merchant-designated account, including the Reserve Account or any holding account. Bank may amend the fees at any time. Bank will give notice to Merchant of such changes in accordance with Applicable Law.

11. Term and Termination

This ACH Addendum becomes effective on the date Merchant is approved for ACH Services or otherwise begins using ACH Services, whichever occurs first, and will remain in effect for so long as the Agreement remains in effect, unless earlier terminated in accordance with this ACH Addendum or the Agreement. LQ and Bank reserve the right to terminate this Addendum or suspend the ACH services at any time, and immediately, following Merchant’s breach of any obligations set forth herein or an event that LQ or Bank deems, in their discretion, to be an event of default reasonably likely to cause financial harm to LQ or Bank or where LQ and Bank, in their discretion, determine that the circumstances otherwise warrant immediate termination or suspension; such termination shall become effective upon providing written notice of such termination to Merchant by any means permitted herein. Bank may terminate this Addendum following direction from any Regulatory Authority or any other authority with regulatory supervision over Bank or Services, to cease or materially limit the exercise or performance of Bank’s rights or obligations under this Addendum.

  1. Early Termination. Should this Addendum terminate prior to the expiration of the then-current term, for any reason, Merchant shall be required to pay LQ an early termination fee in an amount equal to the greater of (a) $495; or (b) the average monthly fees due to LQ under the Addendum times the number of months remaining in the then-current term, which shall be determined based on the average monthly fees assessed during the term of the Addendum prior to termination. Merchant expressly understands that the foregoing fee is not a penalty but rather a reasonable estimate of Bank losses due to early termination. Merchant expressly agrees that such fees are cumulative of Bank’s rights and remedies, and that Bank reserves the right to seek all legal recourse permitted hereunder.
  2. Effect of Termination. Any termination of this Addendum shall not affect any of Bank’s rights and Merchant’s obligations with respect to Entries initiated by Merchant prior to such termination, of the payment obligations of Merchant with respect to services performed prior to termination, or any other obligations that survive termination of this Addendum. Upon termination of this Addendum for any reason at any time, Merchant agrees to pay in addition to any other amounts required by the Addendum (i) any unpaid fees or invoices due; and (ii) any damages, losses, expenses, fees, fines, penalties, and adjustments Bank incurs in connection with this Addendum. Merchant authorizes Bank to debit Merchant’s Designated Account to deduct amounts Merchant owes under this Section, or to deduct such amounts from the Reserve Account. Merchant is responsible for any collection fees, legal fees, and other expenses Bank incurs in recovering delinquent amounts. This Section 11 shall survive termination of this Addendum.

12. Disclaimers of Warranties

EXCEPT AS OTHERWISE SET FORTH IN THIS ADDENDUM, EACH PARTY SPECIFICALLY DISCLAIMS ALL WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, ARISING OUT OF OR RELATED TO THIS ADDENDUM, INCLUDING ANY WARRANTY OF MERCHANTABILITY, OR FITNESS FOR A PARTICULAR PURPOSE, EACH OF WHICH IS HEREBY EXCLUDED BY BOTH PARTIES UNDER THIS ADDENDUM.

EXCEPT AS OTHERWISE SET FORTH IN THIS ADDENDUM, BANK’S SERVICES AND BANK SYSTEMS ARE PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT ANY REPRESENTATION OF WARRANTY, WHETHER EXPRESSED, IMPLIED OR STATUTORY, INCLUDING, WITHOUT LIMITATION ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE OR NON-INFRINGEMENT OF INTELLECTUAL PROPERTY RIGHTS. USE OF BANK SOFTWARE SERVICES OR BANK SYSTEMS IS AT MERCHANT’S OWN RISK. BANK DOES NOT WARRANT THE SERVICES OR BANK SYSTEMS WILL MEET MERCHANT’S REQUIREMENTS, BE CONTINUOUS, UNINTERRUPTED, SECURE, TIMELY, ERROR-FREE, WITHOUT BREACHES OF SECURITY, WITHOUT DELAYS OR THAT DEFECTS WILL BE CORRECTED. BANK SHALL NOT BE RESPONSIBLE FOR ANY SOFTWARE SERVICE OR BANK SYSTEM INTERRUPTIONS OR SERVICE FAILURES THAT MAY AFFECT THE SERVICES OF MERCHANT.

THIS DISCLAIMER OF WARRANTY, SECTION 12 (DISCLAIMERS OF WARRANTIES), SHALL APPLY TO THE FULLEST EXTENT PERMITTED BY LAW IN THE APPLICABLE JURISDICTION.

13. Limitation of Liability

IN THE PERFORMANCE OF THE SERVICES REQUIRED BY THIS ADDENDUM, BANK AND PROCESSOR SHALL BE ENTITLED TO RELY SOLELY ON THE INFORMATION, REPRESENTATIONS, AND WARRANTIES PROVIDED BY MERCHANT PURSUANT TO THIS ADDENDUM, AND SHALL NOT BE RESPONSIBLE FOR THE ACCURACY OR COMPLETENESS THEREOF. BANK AND PROCESSOR SHALL BE ONLY RESPONSIBLE FOR PERFORMING THE SERVICES EXPRESSLY PROVIDED FOR IN THIS ADDENDUM AND SHALL BE LIABLE ONLY FOR ITS GROSS NEGLIGENCE OR WILLFUL MISCONDUCT IN PERFORMING THOSE SERVICES. BANK SHALL NOT BE RESPONSIBLE FOR MERCHANT’S ACTS OR OMISSIONS (INCLUDING, WITHOUT LIMITATION, THE AMOUNT, ACCURACY, TIMELINESS OF TRANSMITTAL OR AUTHORIZATION OF ANY ENTRY RECEIVED FROM MERCHANT) OR THOSE OF ANY OTHER PERSON, INCLUDING, WITHOUT LIMITATION, ANY FEDERAL RESERVE FINANCIAL INSTITUTION, ACH OPERATOR OR TRANSMISSION OR COMMUNICATIONS FACILITY, ANY RECEIVER OR RDFI (INCLUDING, WITHOUT LIMITATION, THE RETURN OF ANY ENTRY BY SUCH RECEIVER OR RDFI), AND NO SUCH PERSON SHALL BE DEEMED BANK’S AGENT.

BANK AND PROCESSOR LIABILITY HEREUNDER SHALL BE LIMITED TO LIABILITY FOR ITS OWN GROSS NEGLIGENCE OR WILLFUL MISCONDUCT. NOTWITHSTANDING THE FOREGOING, IN NO EVENT SHALL BANK OR PROCESSOR BE LIABLE FOR ANY CONSEQUENTIAL, SPECIAL, INCIDENTAL, PUNITIVE OR INDIRECT LOSS OR FOR ANY LOST OR IMPUTED PROFITS OR REVENUES OR COSTS OF COVER ARISING FROM OR RELATED TO THE SERVICES PROVIDED UNDER THIS ADDENDUM, OR ANY OTHER DAMAGE WHICH MERCHANT MAY INCUR OR SUFFER IN CONNECTION WITH THIS ADDENDUM, WHETHER OR NOT THE LIKELIHOOD OF SUCH DAMAGES WAS KNOWN OR CONTEMPLATED BY BANK AND REGARDLESS OF THE LEGAL OR EQUITABLE THEORY OF LIABILITY WHICH MERCHANT MAY ASSERT, INCLUDING, WITHOUT LIMITATION, LOSS OR DAMAGE FROM SUBSEQUENT WRONGFUL DISHONOR RESULTING FROM BANK’S ACTS OR OMISSIONS PURSUANT TO THIS ADDENDUM. WITHOUT LIMITING THE GENERALITY OF THE FOREGOING PROVISIONS, BANK AND PROCESSOR SHALL BE EXCUSED AND HELD HARMLESS FOR FAILING TO ACT OR DELAY IN ACTING IF SUCH FAILURE OR DELAY IS CAUSED BY LEGAL CONSTRAINT.

NOTWITHSTANDING ANYTHING TO THE CONTRARY, MERCHANT’S EXCLUSIVE REMEDIES FOR ANY AND ALL CLAIMS RELATED TO THE SERVICES PROVIDED HEREUNDER SHALL BE LIMITED TO THE AMOUNT RECOVERABLE BY BANK FROM THE RDFI, OR ANY OTHER THIRD PARTY PURSUANT TO THE NACHA RULES.

14. Indemnification

Merchant will defend, indemnify and hold Bank and Processor and their respective officers, directors, employees, agents and suppliers harmless from and against all claims, actions, proceedings, damages, losses, judgments, settlements, penalties, fines, costs and expenses (including attorneys’ fees) arising from any third-party claim in connection with (a) Merchant’s breach of its obligations or undertakings, covenants or representations or warranties under this Addendum; (b) the gross negligence or willful misconduct of Merchant in connection with its performance of its obligations under this Addendum; (c) Merchant’s violation of Applicable Law; (d) Merchant’s Data Breach; (e) the breach, with respect to any Entries initiated by the Merchant, of any of the warranties contained in the Nacha Rules, except those due to the negligence of Bank; (f) any fines imposed on Bank due to breaches of the Nacha Rules by Merchant; (g) Merchant’s use of the Services, including the failure of Merchant to perform its obligations under the Applicable Laws; or (h) any allegation that the Bank is responsible for any act or omission of Merchant or any other person or entity associated with or affected by the services to be performed hereunder, including but not limited to any Receiver, Receiving Depository Financial Institution, or any federal reserve financial institution. Merchant shall further indemnify and hold the Bank and Processor and their respective officers, directors, employees, agents and suppliers harmless from and against all claims, actions, proceedings, damages, losses, judgments, settlements, penalties, fines, costs and expenses (including attorneys’ fees) arising from any third-party claim (i) in connection with any fraudulent activity related to the Services, including unauthorized Entries; or (ii) related to the obligations owed to or by Merchant or any third party retained by it.

15. Relationship of the Parties

It is understood that both Parties hereto are independent contractors and engage in the operation of their own respective businesses and in performing their respective obligations hereunder. Each Party shall be fully responsible for its own employees, servants and agents, and the employees, servants, and agents of one Party shall not be deemed to be employees, servants, and agents of the other Party for any purpose whatsoever. Nothing in this Addendum or in the working relationship being established and developed hereunder shall be deemed, nor shall it cause, Bank, Processor, and Merchant to be treated as partners, joint venturers, or otherwise as joint associates for profit.

16. Media and Records

All media, Entries, security procedures and related records used by Bank for transactions contemplated by this Addendum shall be and remain Bank’s property. Bank may, at its sole discretion, make available such information upon Merchant’s request. Any expenses incurred by Bank in making such information available to Merchant shall be paid by Merchant.

17. Cooperation in Loss Recovery Efforts

In the event of any damages for which Bank or Merchant may be liable to each other or to a third party pursuant to the services provided under this Addendum, Bank and Merchant will undertake reasonable efforts to cooperate with each other, as permitted by Applicable Law, in performing loss recovery efforts and in connection with any actions that the relevant party may be obligated to defend or elects to pursue against a third party.

18. Amendments

From time to time, Bank may amend the terms of this Addendum, including without limitation, any cut-off time, any Business Day, Bank’s ACH guidelines, and any schedule or exhibit attached hereto. Except as expressly provided otherwise in this Addendum or Applicable Law, any such changes generally will be effective immediately upon notice to Merchant or as described in other writing provided to Merchant by Bank. Merchant will be deemed to accept any such changes if it accesses or uses any of the Services after the date on which the change becomes effective. Merchant will remain obligated under this Addendum, including without limitation, being obligated to pay all amounts owing hereunder, even if Bank amends this Addendum. Notwithstanding anything to the contrary in this Addendum, if Bank believes immediate action is required for its security or the security of customer funds, Bank may immediately initiate changes to any security procedures and provide prompt subsequent notice thereof to Merchant.

19. Survival

Provisions of this Addendum that, by their nature, should survive termination shall survive termination (including, but not limited to, Sections 1 (Definitions), 3 (Party Representations and Warranties), 4 (Authorization), 9 (Security Procedures), 11 (Term and Termination), 12 (Disclaimers of Warranties), 13 (Limitation of Liability), 14 (Indemnification), 15 (Relationship of the Parties), 16 (Media and Records), 17 (Cooperation in Loss Recovery Efforts), 19 (Survival)).

Schedule A: Definitions

“Addendum” means this ACH Processing Addendum and documents, policies or procedures referenced herein.

“Applicable Law” means any federal, state and local statutes, rules, regulations, regulatory guidelines and judicial or administrative interpretations related to this Addendum, the Services or Bank, as well as any rules or requirements established by any Regulatory Authority with oversight over Bank, any laws and regulations regulating unfair, deceptive and abusive acts or practices, all anti-money laundering laws and regulations, including the Bank Secrecy Act as amended from time to time, the USA PATRIOT ACT of 2001, regulations administered by the Office of Foreign Assets Control (“OFAC”) or Financial Crimes Enforcement Network, the Gramm-Leach-Bliley Act, as amended from time to time, Nacha Rules and the Uniform Commercial Code.

“Business Day” means Monday through Friday, excluding federal banking holidays.

“Merchant” shall have the meaning set forth in the preamble. For the purposes of this Addendum, Merchant shall also include any Authorized User.

“Entry” or “Entries” has the meaning specified in the Nacha Rules and shall also mean the data received from Merchant under this Addendum for Bank to initiate an Entry.

“In-Process Entries” means the aggregate dollar amount of all credit or debit Entries initiated or submitted by Merchant and in process on any date for which settlement has not occurred with respect to credit Entries, or the applicable period for the return of items has not expired with respect to debit Entries.

“Nacha Rules” means the Operating Rules and Operating Guidelines of Nacha and any other guidance or rules issued by Nacha from time to time.

“Overlimit Entry” means an Entry in the amount of which would cause the aggregate amount of In-Process Entries to exceed the ACH Exposure Limit.