Laserfiche WebLink
<br />Part 2b. Description of Payment Card Business <br />Describe how and in what capacity your business <br />stores, processes, and/or transmits cardholder data. <br />Bluefin Payment Systems LLC (Bluefin), designated and <br />assessed as a Level 1 Service Provider, maintains <br />payment gateway and independent sales organization <br />(ISO) functions. Bluefin enables merchants to accept <br />CHD transactions via a virtual terminal solution and <br />facilitates the connection of merchants to payment <br />processors for processing CHD transactions. <br />Bluefin stores, processes, and transmits cardholder via: <br />Card-Present: <br />•Merchant-Owned POI: Full Track Data <br />Card-Not-Present: <br />Virtual Terminal: PAN, Expiry, Cardholder Name, Card <br />Validation Code <br />E-Commerce: PAN, Expiry, Card Validation Code <br />API: PAN, Expiry, Card Validation Code <br />PIN / Debit: <br />Merchant-Owned POI: Full Track Data, PIN / PIN Block <br />Describe how and in what capacity your business is <br />otherwise involved in or has the ability to impact the <br />security of cardholder data. <br />Bluefin stores, processes, and transmits cardholder via: <br />Card-Present: <br />•Merchant-Owned POI: Full Track Data <br />Card-Not-Present: <br />Virtual Terminal: PAN, Expiry, Cardholder Name, Card <br />Validation Code <br />E-Commerce: PAN, Expiry, Card Validation Code <br />API: PAN, Expiry, Card Validation Code <br />PIN / Debit: <br />Merchant-Owned POI: Full Track Data, PIN / PIN Block <br />Part 2c. Locations <br />List types of facilities (for example, retail outlets, corporate offices, data centers, call centers, etc.) and a <br />summary of locations included in the PCI DSS review. <br />Number of facilities <br />Type of facility of this type Location(s) of facility (city, country) <br />Corporate Office 3 Atlanta, GA US <br />Tulsa, OK, US <br />Waterford, Ireland (NOC, Dev) <br />Data Center 2 Atlanta, GA US <br />PCI DSS v3.2.1 Attestation of Compliance for Onsite Assessments – Service Providers, Rev. 1.0 <br />© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. <br />June 2018 <br />Page 4