Purchase Terms
PURCHASE ORDER TERMS AND CONDITIONS
These terms and conditions govern the purchase of goods and/or services identified on the Purchase Order (“PO”) by the Nuvei entity identified on the face of the PO or otherwise issuing the PO (“Buyer”) and the person, firm, company or organization whose name appears on the PO or who accepts the PO (“Supplier”).
1. DEFINITIONS
1.1. “Agreement” means these Purchase Order (“PO”) Terms together with the Purchase Order and any additional documents which have been agreed by both parties and expressly referred to therein.
1.2. “Confidential Information” shall have the meaning given in clause 13 below.
1.3. “PO Terms” means the terms and conditions detailed in this document.
1.4. “Purchase Order” means the document in which Buyer specifies the goods and/or services to be provided by the Supplier and the corresponding fees.
1.5. “Supplier” means the company supplying the goods and/or services to the Buyer as identified in the Purchase Order.
2. APPLICATION OF TERMS
2.1. Supplier agrees to deliver the goods and/or services as described in the Purchase Order in accordance with the Agreement.
2.2. Additional or different terms which are not expressly agreed by both parties, for example in the Supplier’s acknowledgement or any other Supplier documents, are hereby rejected and shall not apply.
2.3. These PO Terms are non-exclusive. Buyer is free to engage others to provide goods and/or services the same as or similar to Supplier's.
2.4. In the event of any conflict or inconsistency among the documents forming the Agreement, the following order of precedence shall apply: (i) any written agreement or statement of work signed by authorized representatives of both parties that expressly states it supersedes these PO Terms; (ii) the commercial terms expressly set out on the face of the Purchase Order; (iii) these PO Terms; and (iv) any other documents expressly incorporated by reference in the Purchase Order. Any Supplier terms, including terms contained in any quotation, proposal, order acknowledgment, invoice, online terms, click-through terms, or other Supplier document, shall not apply unless expressly accepted in writing by Buyer.
3. PRICES AND TAXES
Unless otherwise stated in the Purchase Order, prices are exclusive of applicable GST, VAT, sales, use, or similar transaction taxes that are legally chargeable to Buyer and separately stated on a valid invoice, but inclusive of all other fees, charges, costs, duties, expenses, and taxes. Supplier shall be responsible for all taxes based on Supplier’s income, personnel, property, or business operations. Buyer may withhold from payments any amounts required to be withheld under applicable law.
4. PAYMENT TERMS AND INVOICES
4.1. In full consideration for the delivery of goods and/or performance of the services and the assignment of rights to Buyer as provided herein, Buyer shall pay Supplier the amount specified in the applicable Purchase Order. Supplier shall submit accurately dated invoices to the Accounts Payable department of the Buyer in accordance with the Purchase Order showing applicable Purchase Order number, description of goods and/or services, quantity, unit prices, extended totals and any other information reasonably requested by Buyer.
4.2. All properly submitted and undisputed invoices will be paid within sixty (60) days of the receipt of the invoice by Buyer unless otherwise expressly agreed. Payment of any invoice shall not constitute acceptance of any goods and/or services. Buyer reserves the right to: (i) make adjustment(s) for errors, shortages, defects in goods or other failure of Supplier to meet any Purchase Order requirements; and (ii) set off any amount owed by Buyer to Supplier against any amount owed to Buyer by Supplier.
4.3 In the event an invoice provides for reimbursement from Buyer of any travel or other related expenses, Supplier’s reimbursement shall be subject to its strict compliance with the Travel Reimbursement Procedures of Buyer, which are subject to change from time to time.
5. SHIPPING AND DELIVERY
Supplier shall deliver the goods and/or services as specified in the applicable Purchase Order. Supplier shall package and ship all goods in accordance with good commercial practice. The applicable Purchase Order number must appear on all shipping containers, packing lists, delivery tickets and bills of lading. Title to and risk in goods shall pass to Buyer upon delivery at the destination nominated by the Buyer. If the delivery of the Products is not completed on time, Buyer reserves the right, in addition to its other rights and remedies, and without liability, to terminate the Purchase Order as to items not yet shipped or services not yet rendered and to purchase substitute Products elsewhere at the expense of the Supplier or to direct Supplier to ship by the most expeditious means available at Supplier’s risk and expense. If goods ordered are destroyed prior to the title passing to Buyer, Buyer may, at its option, cancel the Purchase Order for such goods, or require delivery of substitute goods of equal quantity and quality at no additional cost to the Buyer. Such delivery will be made as soon as commercially practicable. Supplier assumes all risk of loss, damage or destruction to any goods rejected by Buyer. Time for delivery shall be of the essence.
6. REPRESENTATIONS AND WARRANTIES
6.1. Supplier represents and warrants that during the period of twelve months (or such longer period as may be prescribed by applicable law) from the date when the goods are delivered to the Buyer or the services are performed, (i) services will be performed with all reasonable care and skill by suitably qualified personnel in accordance with best industry practice and (ii) all goods and services provided will be (a) in accordance with the Agreement, (b) free from defects in design, materials, workmanship and manufacture, (c) of satisfactory quality, (d) fit for the purposes communicated by Buyer or if not communicated by the Buyer fit for the purposes as can be reasonably deemed, and (e) in conformance with specifications, if any.
6.2. Supplier agrees that it will make spare parts available to Buyer for a period of five (5) years from the date of shipment at Supplier’s then current price less applicable discounts.
6.3. Taxes: Supplier represents and warrants that any and all applicable taxes and withholdings payable by the Supplier will be promptly paid by Supplier to the applicable governmental authority.
6.4. The foregoing warranties are in addition to all other warranties, express or implied, and shall survive the delivery, performance, inspection, acceptance or payment by Buyer. Buyer’s inspection, test, approval, acceptance or use of any goods or services will not relieve Supplier of any warranties specified herein or otherwise applicable. If Buyer identifies a warranty problem during the warranty period, Buyer will notify Supplier and may, at its sole option: (i) require Supplier to correct any defect or nonconformance; (ii) return or reject deficient or nonconforming goods and/or services for a full refund of amounts paid for those deficient or non-conforming goods and/or services; or (iii) correct the deficient or nonconforming goods and/or services itself at a reasonable cost and charge Supplier the cost of such correction. Replacement or repaired goods or services shall be warranted for the remainder of the warranty period or six months, whichever is longer.
7. TERMINATION, CANCELLATION OR CHANGE OF PURCHASE ORDERS
7.1. Buyer may cancel any Purchase Order, in whole or in part, before delivery of the applicable goods and/or services without liability for charges or fees unless otherwise expressly agreed in writing by Buyer. Buyer may also terminate any Purchase Order, in whole or in part, for convenience upon thirty (30) days’ written notice to Supplier. Upon any such termination, Buyer shall pay Supplier only for conforming goods delivered and accepted by Buyer and services properly performed and accepted by Buyer before the effective date of termination. Supplier shall not be entitled to any lost profits, cancellation charges, restocking fees, unamortized costs, early termination fees, or other termination-related charges unless expressly stated in the Purchase Order and agreed in writing by Buyer.
7.2. Buyer may request, and Supplier shall not unreasonably withhold its consent to, changes to the Agreement subject to an equitable adjustment in the price, delivery schedule, or both, where appropriate.
7.3. Buyer may terminate any Purchase Order upon written notice to Supplier at any time if Supplier: (i) fails to perform or otherwise materially breaches any term of the Purchase Order and, where capable of remedy, such failure or breach is not remedied within seven (7) days of Buyer’s notice to do so; (ii) files a petition in bankruptcy, becomes insolvent, or dissolves; or (iii) assigns or attempts to assign the Purchase Order to a third party without written consent of Buyer.
7.4. Upon cancellation or termination of a Purchase Order for any reason, Supplier shall promptly deliver to Buyer, at Supplier’s expense and in accordance with Buyer’s instructions, all completed or in-progress work product, deliverables, Buyer materials, and Buyer Confidential Information, subject to Buyer’s obligation to pay undisputed amounts properly due under the Agreement.
7.5. The cancellation or termination of the Purchase Order shall not affect any obligation of the parties incurred before the termination date.
8. INDEPENDENT CONTRACTOR SERVICES
The parties agree that Supplier is an independent contractor for all purposes, without express or implied authority to bind Buyer by contract or otherwise. Supplier is responsible for all costs and expenses incident to performing its obligations under any Purchase Order and shall provide its own supplies and equipment. The Supplier’s personnel are not employees of Buyer. The Supplier will be solely responsible for payment of all compensation owed to the Supplier’s personnel, as well as for payment of employment related taxes and worker's compensation insurance. The Supplier agrees to fully indemnify Buyer against any and all claims, costs and expenses arising in connection with the Supplier’s breach of this Agreement.
9. OWNERSHIP
9.1. Buyer shall own all custom work product, deliverables, reports, documentation, and other materials specifically created for Buyer under a Purchase Order, including all intellectual property rights therein, upon creation. All tools and equipment supplied by Buyer to Supplier shall remain the sole property of Buyer.
9.2. Supplier and its licensors shall retain ownership of all pre-existing materials, software, tools, templates, methodologies, processes, know-how, and other intellectual property not created specifically for Buyer under the Purchase Order (“Supplier Background IP”). To the extent any Supplier Background IP is incorporated into or necessary to use the goods, services, or deliverables, Supplier grants Buyer a perpetual, worldwide, royalty-free, fully paid-up, transferable license to use, reproduce, display, perform, and otherwise exploit such Supplier Background IP as necessary for Buyer to receive the benefit of and use the goods, services, and deliverables.
9.3. Buyer shall have the right to reproduce all instructions, manuals or other materials provided by Supplier in connection with the Products, provided that the reproduction is solely for its internal use.
10. INDEMNITY
10.1. Supplier shall indemnify, defend, and hold harmless Buyer and Buyer’s officers, directors, employees, successors, assigns, agents, and customers from and against any, and all claims, actions, liabilities, damages, losses, costs, and expenses (including legal fees) arising out of or in any way connected with the goods and/or services provided under any Purchase Order including without limitation: (i) defective workmanship, quality of material or service (ii) any claim by a third party alleging that goods or services, the results of such services, or any other products or processes provided under any Purchase Order infringe a patent, copyright, trademark, trade secret or other proprietary right of a third party, whether such are provided alone or in combination with other products, software or processes; (iii) Supplier’s failure to comply with any applicable law, statute, rule or regulation, including without limitation, related to privacy and publicity; or (iv) death or bodily injury to any person, or damage or destruction to property caused by the Supplier.
10.2. Should Buyer’s use, or use by its employees, contractors, subcontractors or customers, of any goods or services purchased from Supplier be threatened by injunction or any legal proceeding, Supplier shall, at is sole cost and expense, either: (i) substitute fully equivalent non-infringing goods or services; (ii) modify such goods or services so that they no longer infringe but remain fully equivalent in functionality; (iii) obtain for Buyer, its employees, contractors, subcontractors or customers the right to continue using such goods or services; or (iv) if none of the foregoing is possible, refund all amounts paid for the infringing goods or services.
11. INSURANCE
Supplier shall maintain, at its own expense, insurance coverage appropriate to the goods and/or services provided under the Purchase Order, including commercial general liability, employer’s liability/workers’ compensation, professional liability/errors and omissions, product liability where applicable, and such other coverage as Buyer may reasonably require. Where Supplier has access to Buyer systems, Personal Data, payment data, customer data, or other sensitive information, Supplier shall also maintain cyber/privacy liability insurance. All policies shall be maintained with reputable insurers and in commercially reasonable amounts, or in such minimum amounts as may be specified in the Purchase Order. Upon request, Supplier shall provide certificates of insurance or other evidence of coverage and, where requested by Buyer, name Buyer as an additional insured.
12. FORCE MAJEURE
Each party shall be excused from performance to the extent directly caused by circumstances beyond its reasonable control, provided that the affected party promptly notifies the other party of the nature, expected duration, and anticipated impact of the event, uses commercially reasonable efforts to mitigate its effects, and resumes performance as soon as practicable. If Supplier’s performance is delayed or prevented for more than thirty (30) days, Buyer may cancel the affected Purchase Order, in whole or in part, without liability other than payment for conforming goods delivered and accepted and services properly performed and accepted before cancellation.
13. CONFIDENTIALITY
The parties will keep confidential any information (whether written or oral) of a confidential nature (including software and manuals) obtained under the Agreement and will not, without the written consent of the other party, disclose that information to any person (other than their employees or professional advisers). This provision will not apply to (a) any information which has been published other than through a breach of the Agreement;
(b) information lawfully in the possession of the recipient before the disclosure under the Agreement took place; (c) information obtained from a third party who is free to disclose it; and (d) information which a party is requested to disclose and, if it did not, could be required by to do so by law.
14. LIMITATION OF LIABILITY
14.1. In no event shall Buyer be liable to Supplier for anticipated or actual lost profits, loss of business, loss of savings, loss of data, or any indirect, special, incidental, punitive, exemplary, or consequential loss or damage, whether arising in contract, tort, negligence, statute, or otherwise, even if Buyer has been advised of the possibility of such damages.
14.2. Buyer’s aggregate liability arising out of or relating to any Purchase Order shall not exceed the amounts paid or payable by Buyer for the goods and/or services giving rise to the claim.
14.3. Nothing in the Agreement shall exclude the parties’ liability for death or personal injury caused by their negligence or for fraud or fraudulent misrepresentation.
14.4. For clarity, any limitation of liability shall not limit Supplier’s obligations or liability under the indemnity, confidentiality, data protection, intellectual property, compliance with laws, fraud, willful misconduct, or gross negligence provisions of the Agreement.
15. COMPLIANCE WITH LAWS
15.1. Supplier shall comply fully with all applicable laws and regulations in the performance of the Agreement.
15.2. Customs: Upon Buyer's request, Supplier will promptly provide Buyer with a statement of origin for all goods.
16. CODE OF CONDUCT
Supplier shall comply with Nuvei’s Third Party Code of Conduct (https://www.nuvei.com/service-pages/third-party-code-of-conduct).
17. DATA PROTECTION
To the extent Supplier has access to Buyer systems, Confidential Information, Personal Data, payment data, customer data, cardholder data, or other sensitive information, Supplier shall use such information only on behalf of Buyer and solely in accordance with Buyer’s instructions, the Agreement, and applicable law. Without limiting the foregoing, where Supplier performs In-Scope Work or otherwise accesses Buyer systems, Confidential Information, Personal Data, payment data, customer data, cardholder data, or other sensitive information, Supplier shall comply with Appendix A (Supplier Information Security Requirements), which is incorporated into the Agreement. Supplier shall implement and maintain appropriate administrative, technical, and organizational safeguards designed to protect such information against unauthorized access, use, disclosure, alteration, loss, or destruction. Supplier shall notify Buyer without undue delay, and in any event promptly after becoming aware, of any actual or suspected unauthorized access to or disclosure, loss, compromise, or misuse of such information. Supplier shall not engage any subcontractor or subprocessor to process Personal Data or access Buyer systems or data without Buyer’s prior written approval. Upon Buyer’s request or upon termination or completion of the applicable Purchase Order, Supplier shall promptly return or securely delete Buyer data. Where required by Buyer or applicable law, Supplier shall enter into Buyer’s data processing agreement, security addendum, or equivalent data protection documentation. Supplier shall indemnify and hold Buyer and Buyer’s affiliates, associates, directors, officers, employees, agents, and independent contractors harmless from any and all claims, liabilities, costs, charges, damages, penalties, expenses, or losses arising from or in connection with Supplier’s breach of this section, Appendix A, or failure to comply with applicable privacy or data protection laws.
18. ACQUIRED RIGHTS
The parties to this Agreement do not intend that any of the Supplier’s employees shall transfer to the employment of Buyer at any time and the Supplier hereby indemnifies Buyer (both for itself and any new service provider) against all costs, claims, liabilities and expenses (including reasonable legal expenses) incurred by Buyer and/or any new service provider in connection with or as a result of any claims or demands associated with any such actual or purported transfer.
19. NON-SOLICITATION
During the term of the Purchase Order, and for 6 months thereafter, Supplier will not directly or indirectly solicit for employment or performance of computer services, or hire or contract with, any employee, Supplier or subcontractor (“Staff”) of Buyer who becomes knows to Supplier in connections with the performance hereunder. In the event Supplier, or any affiliate of Supplier hires or contracts with any Staff of Buyer contrary to this Section, Supplier agrees to pay Buyer, as liquidated damages and not as a penalty, an amount equal to all compensation including salary, wages, bonuses, commissions and employee benefits, which such Staff received from Buyer during the last six (6) month period preceding such hiring or contracting. If such Staff worked for Buyer for a period of fewer than six (6) months, the payment will be six (6) times the average monthly compensation for the period worked.
20. ASSIGNMENT
Supplier shall not assign or subcontract its obligations under the Purchase Order, in whole or in part, or any interests therein, without Buyer’s written consent. If Buyer consents to any assignment or subcontract, Supplier shall remain liable and responsible for all of its obligations hereunder, and shall guarantee performance by its assignee or subcontractor.
21. GENERAL
21.1. Supplier warrants that it is in compliance with all applicable import or export laws and regulations. Supplier will otherwise comply in any and all respects with all applicable laws, ordinances, rules and regulations and other legal requirements that apply to this Agreement.
21.2. Supplier will not use any payment or other benefit derived from Buyer to offer, promise or pay any money, gift or any other thing of value to any person for the purpose of influencing official actions or decisions affecting this Agreement, while knowing or having reason to know that any portion of this money, gift or thing will, directly or indirectly, be given, offered or promised to an employee, officer or other person acting in an official capacity for any government or agency or any political party, party official or candidate for political office.
21.3. Supplier will at all times refrain from engaging in any illegal, unfair or deceptive trade practices or unethical business practices. Supplier shall at its expense obtain any and all permits, licenses, authorizations, and/or certificates that may be required in any jurisdiction or by any regulatory or administrative agency in connection with its activities hereunder. Supplier shall adhere to Buyer rules and policies and disseminate current information and materials as announced or provided from time to time by Buyer to Supplier.
21.4. If any provision of the Agreement shall be deemed to be invalid, illegal or unenforceable, the validity, legality and enforceability of the remaining provisions shall not in any way be affected or impaired thereby.
21.5. Any party’s delay or failure to exercise any of its rights under the Agreement shall not be deemed or construed to operate as that party’s waiver of any such rights.
21.6. All notices, and other communications hereunder shall be in writing, and shall be addressed to Supplier’s address for payment or to an authorized Buyer representative, and shall be considered given when (a) delivered personally, (b) sent by confirmed facsimile, (c) sent by commercial overnight courier with written verification receipt, or (d) three (3) days after having been sent, postage prepaid, by first class or certified mail.
21.7. The Agreement contains the whole agreement between the parties and supersedes all previous written or oral agreements relating to the subject matter. The parties acknowledge and agree that (a) they have not been induced to enter into the Agreement by any representation warranty or other assurance not expressly incorporated into it; and (b) in connection with the Purchase Order their only rights and remedies in relation to any representation warranty or other assurance are for breach of the Purchase Order and that all other rights and remedies are excluded. This provision shall not affect the parties’ rights or remedies in relation to any fraud or fraudulent misrepresentation.
21.8. The Purchase Order does not and is not intended to confer any benefit on nor create any right exercisable or enforceable by any third party.
22. GOVERNING LAW AND JURISDICTION
This Purchase Order shall be governed by and construed in accordance with: (a) the laws of the State of New York, without regard to its conflict of laws principles, if the Buyer identified in the applicable Purchase Order is Nuvei or an entity directly or indirectly controlled by Nuvei whose principal place of business is located in Canada, the United States, Mexico, Central America, South America, or the Caribbean; or (b) the laws of England and Wales, without regard to its conflict of laws principles, if the Buyer identified in the applicable Purchase Order is Nuvei or an entity directly or indirectly controlled by Nuvei whose principal place of business is located outside the jurisdictions identified in subsection (a). For Purchase Orders governed by the laws of the State of New York, the parties irrevocably submit to the exclusive jurisdiction of the state and federal courts located in New York, New York. For Purchase Orders governed by the laws of England and Wales, the parties irrevocably submit to the exclusive jurisdiction of the courts of England and Wales. The United Nations Convention on Contracts for the International Sale of Goods shall not apply to this Purchase Order. Supplier agrees that it will comply with all applicable laws relating to the performance of its obligations under the Purchase Order, including obtaining all necessary approvals, licenses, permits, and authorizations applicable to its business and the goods and/or services provided under the Purchase Order. If any provision of this Purchase Order, other than those provisions relating to the assignment of rights to Buyer, is held unenforceable by a court of competent jurisdiction, the remainder of this Purchase Order shall remain in full force and effect. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE PARTIES HEREBY IRREVOCABLY WAIVE ANY RIGHT TO TRIAL BY JURY IN ANY ACTION, PROCEEDING, OR COUNTERCLAIM ARISING OUT OF OR RELATING TO THIS PURCHASE ORDER.
APPENDIX A - SUPPLIER INFORMATION SECURITY REQUIREMENTS
1. Scope
a) These Security Requirements apply to Suppliers, companies and individuals (external service providers, outsourcing, insourcing, cloud service provider, software developer, hardware provider), who perform professional services for the Buyer when performing any action, activity or work under the Agreement where any of the following occur (hereinafter referred to as “In-Scope Work”):
i. Collection, storage, handling, processing, backup, disposal, and/or access to confidential, proprietary and/or trade secret data of the Buyer, including data of others that the Buyer is obligated to protect, if any (hereinafter collectively referred to as “In-Scope Information”);
ii. Providing or supporting Buyer branded applications and/or services even when using non-Buyer Information;
iii. Connection to the Buyer’s Non-public Information Resources;
iv. Development of any software to Buyer’s custom specifications for which the Buyer has been charged; or
v. Application hosting and development for the Buyer and/or its customers.
b) With respect to personnel under Supplier’s direct control, Supplier shall:
i. Ensure that its affiliates, employees and temporary workers performing In-Scope Work are aware of these Security Requirements and comply to the Security Requirements when performing In-Scope Work.
c) With respect to suppliers and personnel not-under Supplier’s direct control, Supplier shall:
i. Include these Security Requirements into its agreements with its subcontractors performing In-Scope Work and shall perform due diligence adequate to ensure compliance by such subcontractors with these Security Requirements when performing In-Scope Work, or
ii. Perform adequate due diligence to ensure adherence of each such subcontractor when performing In-Scope Work.
iii. Ensure In-Scope Work implements and complies with information security controls, policies, processes and procedures substantially equivalent or similar to these Security Requirements.
d) These Security Requirements are NOT intended to apply to products or applications acquired from the Supplier by the Buyer for use in the Buyer secure environment (on-prem).
In accordance with the foregoing, Supplier shall:
2. Physical Security
Ensure that all Information Resources are located in secure physical facilities with access limited and restricted to authorized individuals only. Monitor and record access to the physical facilities.
3. Network security
a) When providing services accessible via the Internet to the Buyer, Supplier shall have Denial of Service (DoS/DDoS) protections in place.
b) Supplier shall protect In-Scope Information within an internal, non-public network, that is only accessible via a network DMZ. Web servers providing service to the Buyer shall reside in the DMZ. Information Resources storing In-Scope Information (such as application and database servers) shall reside in a trusted internal network.
c) Supplier shall maintain a high-level network diagram, that shall provide details about placement of information resources and security devices such as (Security Gateways, servers, DMZs, IDS/IPS, DoS/DDoS protections, etc.) within the network that are and/or will be used to support the Buyer.
d) Supplier shall use Strong Encryption (TLS v1.2 or higher) for the transfer of In-Scope Information outside of Buyer-controlled or Supplier-controlled networks or when transmitting In-Scope Information over any untrusted network. This also applies to In-Scope Information contained in emails or emails attachments.
e) Supplier shall apply Strong Encryption, based on security best practices, on In-Scope Information.
f) Supplier shall enforce Strong Authentication/MFA for any remote access to Information Resources.
4. System Security
Supplier shall:
a) Assign security administration responsibilities for configuring systems and devices to specific individuals.
b) Define a process and document in procedure to remediate security vulnerabilities of Information Resources within a reasonable time. Critical and high severity vulnerabilities shall be fixed immediately.
c) Apply appropriate security patches promptly based on potential risk that a given vulnerability is or can be exploited.
d) Scan Information Resources with industry-standard security vulnerability scanning software to detect security vulnerabilities, at least quarterly.
e) Harden all Information Resources including, but not limited to, removing, or disabling unused networking and other computing services (e.g., finger, rlogin, ftp, simple Transmission Control Protocol/Internet Protocol (TCP/IP) services, etc.) and installing a system firewall, Transmission Control Protocol (TCP) wrappers or similar technology.
f) Change all default account names and default passwords.
5. Software and Data Integrity
Supplier shall:
a) Separate non-production Information Resources and In-Scope Information from production Information Resources and In-Scope Information.
b) Document procedures for the backup, recovery and eventual destruction of In-Scope Information.
c) Isolate Buyer’s applications and In-Scope Information from any other clients or Supplier’s own applications and information by using physically separate servers.
d) Limit access to In-Scope Information explicitly to authorized persons or systems, authorized in the Agreement.
e) Document processes and controls in place to detect and terminate unauthorized attempts to access, collect, store, handle and/or dispose of In-Scope Information.
f) Have current anti-malware software installed and running to scan for and promptly remove or quarantine viruses and other malware (as commercially available and to the extent practicable).
g) Have a documented change control process including back-out procedures, testing and approval for all changes to In-Scope environments.
h) For all software developed under the Agreement, review such software to find and remediate security vulnerabilities prior to initial deployment and upon any modifications and updates, including source code vulnerability scanning, any combination of automated and/or manual processes and procedures. Scan results and remediation plans must be made available to the Buyer upon request.
i) For all software used, furnished and/or supported under the Agreement, review such software to find and remediate security vulnerabilities prior to initial deployment and upon any modifications and updates based on potential risk that a given vulnerability is or can be exploited.
j) Perform quality assurance testing for the security components (e.g., testing of identification, authentication and authorization functions), as well as any other activity designed to validate the security architecture, during initial implementation and upon any modifications and updates.
k) Use Strong Encryption for the storage of In-Scope Information including secure management of cryptographic keys.
6. Monitoring and Auditing Controls
a) Protect security-related audit logs from unauthorized modification, review them frequently (automatically via automated system and real-time alerts), resolve logged security problems and anomalies in a timely manner.
b) For applications & database audit logs Supplier shall have database transaction logging features enabled (if supported), or other mechanism that logs all modifications to In-Scope Information stored within the database including timestamp, UserID and information modified.
c) Retain logs and make them available to the Buyer for a minimum of twelve (12) months (on-line or on backup media).
7. Identification and Authentication
Supplier shall:
a) Limit, to the minimum extent as possible, privileged accounts (also known as root, privileged, or super user) access to system administrator.
b) Enforce the rule of least privilege by requiring application, database, network and system administrators to restrict access by users to only the commands, data and Information Resources necessary for them to perform authorized functions. Supplier shall ensure that the use of Buyer’s Information Resources by Supplier or any of its affiliates (or by any other person/entity on Supplier’s behalf) shall only be for the performance of those Services or functions explicitly authorized in the Agreement.
c) Document the UserID lifecycle management process for all Information Resources and across all environments (usually referred to as Access Management Procedure) that includes: processes for approved account creation, timely account removal, account modification, user account reactivation verification, review of access privileges and account validity to be performed at least annually, and the following minimal settings: assign unique UserIDs to individual users, limit failed login attempts, activate a secure locking screensaver requiring authentication.
d) Use an automated authentication method based on the sensitivity of In-Scope Information. Authentication credentials shall be protected using Strong Encryption at-rest and in-transit.
e) When passwords are used, they shall be complex and shall meet best practice requirements for structure, expiry, secure method to provide re-set authentication credentials.
f) Remove user accounts when no longer needed or when the user contract is terminated.
8. Reporting Security Breach
Supplier shall:
a) Create and document a procedure to be followed in the event of a suspected security breach/ attack/ intrusion upon, unauthorized access to, loss of, or other security incident involving In-Scope Information.
b) Notify the Buyer by contacting the Chief Information Security Officer (CISO) within 24 hours of any security incident that pertain to the Buyer’s Information Resources and promptly take action to address them.
c) Provide the Buyer with regular status updates, including, but not limited to, actions taken to resolve such incident, at mutually agreed intervals or times for the duration of the incident and, within seven (7) calendar days of the closure of the incident, provide the Buyer with a written report describing the incident, actions taken during its response and plans for future actions to prevent a similar incident from occurring.
9. PCI-DSS Requirements
This PCI-DSS Requirements section is applicable only if the Supplier, as part of the services, processes PCI/card data information:
a) The Buyer is PCI DSS certified, therefore the Supplier with whom cardholder data (/account data) is shared (if applicable), or that could affect the security of cardholder data must meet the same level of validation as the Buyer, or based on card brands, acquiring banks, laws and regulations, risk appetite, customers commitments. Keep in mind that meeting other security compliance guidelines and security certifications does not guarantee PCI DSS guidelines are met.
b) Supplier acknowledges its responsibility for the security of cardholder data the Supplier possess or otherwise store, process or transmit on behalf of the Buyer, or to the extent that it could impact the security of the Buyer’s cardholder data environment (if applicable). This acknowledgement depends on the agreement between the Parties and the responsibilities assigned to each Party, as applicable per the provided Deliverables and/or services.
c) Supplier must maintain communication with the Buyer as to the Supplier’s PCI DSS compliance status, or other necessary security measure and controls (as agreed), at least annually (if such compliance is applicable to the Agreement).
On this page
Ready to grow everywhere?
Get started with Nuvei – the growth infrastructure for every payment, everywhere. One intelligent system, built to scale.