Laserfiche WebLink
ii. In the event of a security intrusion, Merchant agrees to fiilly cooperate with a third party approved <br />Payment Card Industry assessor and/or representative to conduct a thorough security review and <br />validate compliance with the Payment Card Industry Data Security Standards (PCI) for protecting <br />Cardholder data; <br />iii. Merchant is responsible for security of Cardholder data in possession- <br />iv. Bank, EPX, Merchant and each payment card brand have ownership?of Cardholder data and may <br />use such data ONLY for assisting these parties in the completion of Transactions, supporting a <br />loyalty program, providing fraud control services, or for other uses specifically required by law; <br />v. In the event this Agreement is terminated by any of the parties, each party agrees to continue <br />to treat account holder data as confidential; <br />vi. Immediately notify Visa USA Risk Management, through its acquirer, of the use of a <br />Merchant Servicer; and <br />vii. Ensure the Merchant Servicer implements and maintains all of the security requirements, as <br />specified in the PCI program. <br />viii. Merchant must ensure PCI compliance of any residual data which may exist. Any residual <br />data which is destroyed must be disposed of in a secure manner. <br />5.4. Use of EPX Systems. Use of software programs approved by EPX and related equipment installed or <br />improved by EPX for use with the EPX System, will be subject to the following: <br />i. Merchant will use and operate the EPX Systems only in accordance with Manuals, as amended <br />from time to time by EPX; <br />ii. If Merchant is using_EPX-provided software, Merchant will install, use and operate the Software <br />only in accordance with the Manuals, as amended from time to time by EPX; <br />iii. In processing Transactions, Merchant shall use only software programs, file formats and <br />processing methods that have been approved and certified by EPX's Integration staff; and <br />iv. Merchant shall be responsible for the custody and control of all passwords provided by EPX to <br />Merchant to access the EPX reporting system. <br />5.5. Compliance with Applicable Law. Merchant represents and warrants that it has obtained all necessary <br />regulatory approvals, certificates and licenses to provide any services it intends to offer and that it is in <br />compliance with the regulations of the Federal Trade Commission and the Federal Communications <br />Commission and shall comply with all present and future federal, state and local laws and regulations <br />pertaining to Transactions, including, without limitation, the Federal Fair Credit Reporting Act, the <br />Federal Truth-in-Lending Act, the Electronic Fund Transfers Act, the Federal Equal Credit Opportunity <br />Act, as amended, and the Telephone Disclosure and Dispute Resolution Act, as applicable. <br />5.6. Web Site Requirements for E-Commerce Merchants. A web site operated by the Merchant that <br />accepts Card Transactions must contain all of the following information: <br />i. Complete description of the services offered; <br />ii. Return merchandise and refund policy; which includes the communication of the return policy <br />during the order process and the requirement that the cardholder must be allowed to select a <br />"click to accept" option or other affirmative button to acknowledge the policy; <br />iii. Terms and conditions must be displayed on the same screen view as the checkout screen used <br />to present the total purchase amount; or <br />iv. Within the sequence of web pages the cardholder accesses during the checkout process. <br />v. Customer service contact including e-mail address or telephone number; <br />vi. Transaction currency; <br />vii. Export or legal restrictions; <br />viii. Delivery policy; <br />ix. Consumer data privacy policy; <br />x. The security method offered for transmission of payment data such as Secure Sockets Layer or <br />3-D Secure; and <br />Initials Pa,e 7 of 19