Third-Party
Processors.
Pintop may use carefully selected providers to support hosting, communications, identity verification, payments, analytics, customer support, security and other functions required to operate its business and deliver contracted services.
External services support specific parts of delivery.
Pintop does not need every provider to process every client’s data. The providers involved depend on the product, hosting model, integrations, payment method, support arrangement and service configuration.
Where a provider processes personal data for Pintop or for a client service, its role, permitted purpose, access and obligations are governed through the applicable contractual and operational arrangements.
The provider schedule contained in a signed Data Processing Agreement or another client-specific document remains authoritative for that engagement.
Provider categories that may support
Pintop services.
The categories below describe the types of functions for which Pintop may engage a third-party provider.
Hosting and infrastructure
Cloud computing, servers, storage, backups, networking, deployment environments and supporting infrastructure.
Communications
Business email, transactional messages, notifications, collaboration, customer communications and related delivery services.
Identity and verification
Identity checks, document validation, biometric or liveness services, address verification and related identity-processing functions.
Payments and billing
Payment processing, invoicing, transaction confirmation, subscription billing and related financial administration.
Analytics and monitoring
Website analytics, service performance, system monitoring, error reporting and operational insight.
Customer and technical support
Helpdesk, ticketing, remote support, issue tracking, service communication and related support operations.
Security and assurance
Security testing, vulnerability management, monitoring, auditing, compliance support and incident-response assistance.
Professional services
Legal, accounting, compliance, audit, tax and other specialist services requiring limited access to relevant information.
Workforce administration
Payroll, pensions, benefits, recruitment, training and other services supporting Pintop’s workforce.
How a provider is
assessed.
The depth of review reflects the provider’s access, processing purpose, data sensitivity and importance to the relevant service.
Define the service
Identify the function the provider performs, the Pintop product or process involved and whether the provider requires access to personal data.
Review data access
Determine the categories, volume, sensitivity, access method, retention and individuals affected by the proposed processing.
Evaluate security
Consider the provider’s access controls, encryption, incident handling, continuity, audit capability and other relevant safeguards.
Confirm processing locations
Identify where information may be hosted, accessed, backed up or otherwise processed and which transfer considerations apply.
Put terms in place
Establish confidentiality, security, processing, deletion, incident and sub-processing obligations appropriate to the service.
Monitor material changes
Reassess the provider where its service, access, locations, ownership, safeguards or role changes materially.
Provider access is governed by purpose and agreement.
Where a provider processes personal data, the relevant terms should limit processing to the authorised service and define the protections expected throughout the relationship.
Processing locations and
international transfers.
A provider may use infrastructure or support personnel in more than one location. The applicable arrangement depends on the service and deployment model.
Primary processing
The main location in which a provider hosts, stores, accesses or otherwise processes the relevant information.
Backup and resilience
Backup, recovery or continuity infrastructure may use another location according to the provider’s service architecture.
Transfer safeguards
Where information is transferred internationally, the relevant legal, contractual and organisational safeguards are applied to the circumstances.
The same provider list does not apply to every client.
A product-specific schedule can provide more useful and accurate information than a single general list covering every possible provider relationship.
Product or service
Identify the exact product, module, integration, training service or corporate function involved.
Provider identity
State the legal or contracting entity providing the relevant service.
Processing purpose
Explain what the provider does and why access to the relevant information is required.
Data categories
Describe the categories of information that may be disclosed, accessed, generated or stored.
Processing locations
Identify the relevant country, region or service location where this is available and applicable.
Applicable safeguards
State the relevant processing agreement, transfer protection or other contractual arrangement.
A provider may be added, replaced or removed as services evolve.
Changes may result from product development, service availability, regional requirements, security findings, commercial decisions or a change in the client’s implementation.
Need the provider details for a specific Pintop service?
Contact Pintop with the relevant product, implementation or contract reference so the request can be matched to the correct service arrangement.
Questions or concerns about a service provider?
Include the relevant client, product, processing activity and provider function so the enquiry can be reviewed against the correct contractual arrangement.
Related privacy and
security documents.
These documents provide additional information about privacy roles, processing agreements and Pintop’s security framework.
