Online Privacy Notice

June 30, 2026

Fidelity National Information Services, Inc. (its subsidiaries and affiliates, collectively “FIS”) recognizes and respects the privacy expectations of individuals and the requirements of applicable regulations in protecting their personal data.

FIS safeguards your privacy rights with respect to any data or information we receive that relates to you as an identified or identifiable natural person. For purposes of this Online Privacy Notice, we will call such data or information “personal data.” Personal data will always be collected, used, disclosed or otherwise processed by FIS in compliance with applicable laws.

This Online Privacy Notice explains how we collect, use, store, share or otherwise process personal data in connection with your use of FIS websites or other digital channels, where we act as the controller your personal data. For further information, please review the FIS Privacy Center (link: Privacy | FIS) which explains FIS’ data processing practices in greater detail.

INFORMATION THAT YOU PROVIDE VOLUNTARILY

We collect personal data you provide voluntarily through our site or our other digital channels.

We do not intentionally collect sensitive personal data, unless you provide us with such data. While there may be free text boxes on the site where you are able to enter any information, we do not intend to process sensitive personal data. You are not required to provide, and should not disclose, sensitive personal data. If you choose to provide any sensitive personal data in this manner, you acknowledge that you consent to the collection and processing of this sensitive personal data in those circumstances.

INFORMATION WE COLLECT AUTOMATICALLY

When you visit our site or access our products online, we collect certain personal data automatically from your device. Specifically, the data we collect automatically includes information, such as your IP address, pixel ID, device type, unique device identification number, browser type, operating system, broad geographic location (e.g., country or city-level location), and other technical information. We also collect information about how your device has interacted with our site, including the pages accessed, current URL, time you visited the site, and links clicked. Collecting this information enables us to better understand the visitors who come to our site, where they come from and what content on our site is of interest to them. We use this information for our internal analytics purposes and to improve the quality and relevance of our site to our visitors.

Information will be collected using cookies and similar tracking technology, as explained further in section Use of Cookies on Website(s) below and our Cookie Notification.

SECURITY

We use appropriate technical and organizational measures to protect the personal data we collect and process about you. The measures we use are designed to provide a level of security appropriate to the risk of processing your personal data.

Please read our Security Statement that summarizes FIS’ information security policies, procedures, and standards including its technical and organizational measures for the security of data.

While we do our best to protect your personal data, privacy incidents are unfortunately becoming more common. In addition to the steps we take to protect your personal data, we believe there are measures you should take to protect yourself as well. We encourage you not to share personal data with others unless you clearly understand the purpose of the individual requesting the information, and have confirmed that you are interacting with legitimate contact. We also recommend you not share any significant personal data via email or voicemail.

While we take precautions to protect your personal data from loss, theft, alteration, or misuse, no system or security measure is completely secure. Any transmission of your personal data is at your own risk, and we expect you will use appropriate measures to protect your personal data as well.

PURPOSES FOR WHICH WE PROCESS YOUR PERSONAL DATA AS A VISITOR TO OUR SITE OR ACCESSING OUR PRODUCTS ONLINE ARE:
  • To administer and manage our site, including to confirm and authenticate your identity, and prevent unauthorized access to restricted areas of our site (for example, we may confirm your IP address matches the location entered into our online forms or may confirm you are not listed as a restricted party with whom we are legally prohibited from doing business)
  • To personalize and enrich your browsing experience by displaying content (including targeted advertising) that is more likely to be relevant and of interest to you
  • To analyze the data of visitors to our site and site traffic information
  • To capture web metrics about the journey of users within our site
  • To determine the company, organization, institution, or agency you work for or with which you are otherwise associated
  • To develop our business and services
  • To deliver products and services to our clients to provide them with information about such products or other legitimate business purposes
  • To provide you with marketing communications
  • To conduct benchmarking and data analysis (for example, regarding usage of our site and demographic analyses of visitors of our site)
  • To understand how visitors use the features and functions of our site
  • To monitor and enforce compliance with applicable terms of use
  • To conduct quality and risk management reviews
  • To enable better management of our events
  • To enable the teams managing events to coordinate their email campaigns and event notifications more effectively
  • To allow for events and webinars sign-up
  • To allow for content download and lead capturing
  • To allow services and information to be delivered effectively to you
  • Any other purpose for which you provided information to FIS
WHEN YOU CONTACT US OR REQUEST US TO CONTACT YOU

Via our website, or other digital channels, you can contact us or ask us to contact you regarding questions, queries, (support) requests, comments or complaints, fill out an application to become a client, merchant or a partner or sign up for an account. When you do this, we collect the information you supply, including your name, company, contact details, the reason you are contacting us, verification you are not a robot and other information you provide us with. You can also contact us by calling us or e-mailing us using, for example, the contact details listed on our website. If you do so, we will collect your name, company, and any other information we need to be of further assistance to you and/or communicate with you.

We use the aforementioned data to answer your questions, comments, complaints, respond to your queries and (support) requests, and to assess your application to become a client or partner. As such, this data is used by us to establish or perform our (future) contract with you and for our legitimate interests in following up with you. We also use the data above for our legitimate interest of conducting business with you and managing our internal administration, for training purposes, for establishing and performing our contract with you, for our legitimate interest of conducting marketing research, so we can improve our products and services and offer our future and existing clients tailored products and services.

GEOLOCATION DATA

We collect and use geolocation information linked to your device when you use our mobile apps, with your permission, and where permitted by local law. FIS uses this data as part of its processes to prevent and detect fraudulent card use and send alerts. For Card Suite applications, geolocation information processed as part of a transaction, as well as transaction history, is retained for up to 365 days and includes point of sale merchant location data. Geolocation data collected in connection with the use of SecurLOCK Equip and MobiMoney, however, is retained for 30 days. Where permitted by local law, FIS may monitor your geolocation information in the background while the mobile app is being used. You can change location permissions at any time either directly in the mobile app or in your device settings.

LEGAL GROUNDS FOR PROCESSING PERSONAL DATA OF VISITORS OF OUR SITE OR ACCESS OUR PRODUCTS ONLINE

FIS processes personal data on the following legal grounds:

  • our legitimate interest in the effective delivery of information and services to you, and the effective and lawful operation of our businesses
  • our legitimate interest in responding to questions, comments, complaints, respond to queries
  • our legitimate interest in developing and improving our sites and digital channels and your user experience
  • explicit consent of the visitor, in which case they have a right to withdraw their consent at any time (see Exercising Your Rights section below)
  • compliance with a legal obligation
  • processing personal data which has been publicly disclosed or legally disclosed within a reasonable scope.
SHARING YOUR PERSONAL DATA

We take care to allow your personal data to be accessed only by those who really need to in order to perform their tasks and duties, and to third parties who have a legitimate purpose for accessing it.

We disclose your personal data to the following categories of recipients:

  • companies belonging to FIS
  • support providers
  • business partners and other participants in the payment ecosystem
  • other third party recipients (including professional advisors, such as law firms, tax advisors or auditors, regulatory authorities, public authorities, other professional bodies, law enforcement in connection with investigations).

For further information, please review the FIS Privacy Center (Privacy | FIS).

FIS may disclose your personal data if regulatory obligations require FIS to do so, if FIS determines such disclosure is legally advisable or necessary in order to protect FIS’ rights, the rights of others, or in order to prevent harm.

RETENTION

We will retain your personal data for as long as necessary to fulfil the purposes for which it was collected and in accordance with applicable law. We establish our retention periods within our company policies.

When we have no ongoing legitimate business need to process your personal data, we will either delete or anonymize it, or, if this is not possible, for example, because your personal data has been stored in backup archives, we will securely store your personal data and isolate it from any further processing until deletion is possible.

Methods of destruction: FIS’ workforce and vendors with access to personal data are required to comply with secure deletion standards in alignment with the latest NIST Guidelines for media sanitization.

CHILDREN’S PRIVACY

FIS does not knowingly solicit or collect personally identifiable information from children under the age of thirteen (13) without verifiable parental consent. If FIS learns that a child under the age of thirteen (13) has submitted personally identifiable information online without parental consent, FIS will take all reasonable measures to delete such information from our databases and to not use such information for any purpose (except where necessary to protect the safety of the child or others as required or allowed by law). If you become aware of any personally identifiable information we have collected from children under thirteen (13), please contact us at privacyoffice@fisglobal.com.

FIS website(s) are not directed at persons under the age of 18. FIS does not knowingly collect, maintain, or use personal data from persons under the age of 18 on any FIS website. If you are under the age of 18 years, please do not register or otherwise provide information to FIS on an FIS website. Minors under 18 years of age may have the personal data that they provide to us deleted by sending an email requesting deletion to privacyoffice@fisglobal.com or via this form.

Please note that, while we make reasonable efforts to comply with such requests, deletion of your personal data does not ensure complete and comprehensive removal of that data from all systems.

USE OF COOKIES ON WEBSITE(S)

Cookies are text files containing small amounts of information, normally consisting of just letter and numbers, which are downloaded to your computer or mobile device when you visit a website. Cookies are then sent back to the originating website on each subsequent visit, or to another website that recognizes that cookie. The information stored in cookies may include personal data, such as an IP address, a username, and a unique identifier. Cookies may also contain non-personal data, such as language settings or information about the type of device a person is using.

Cookies may serve various purposes, and the cookies used on FIS’ websites have been categorized as follows: (1) necessary (essential) - these cookies are necessary for the website to function and cannot be switched off in FIS systems, (2) statistics (performance) - these cookies allow FIS to count visits and traffic sources, so FIS can measure and improve the performance of the website, (3) preferences (functional) - these cookies enable the website to provide enhanced functionality and personalization to you during your visit, and (4) marketing (including social media) - these cookies may be set through FIS website by our advertising partners. They may be used by those companies to build a profile of your interests and show you adverts relevant to your interest for other sites and enable you to share our content in social media.

FIS uses only strictly necessary cookies unless the user has consented to the use of additional type of cookies. However, blocking some types of cookies may impact on your experience of the website and the services FIS is able to offer. For more information on FIS’ use of cookies and your options, please review the FIS Cookie Notification and the description of cookies available in the cookies banner.

You may manage your cookies preferences via cookie banner available on FIS’ websites. By making no selection only necessary cookies will be used. You may change your cookies preferences at any time by using cookies banner.

FIS WEBSITES MAY BE LINKED TO OTHER WEBSITES

FIS websites may contain links to other websites. As you navigate our websites, you may click on links that take you to websites that belong to other business units or business partners affiliated with FIS. In addition, we may include links to third-party websites, which are not FIS business units or FIS affiliates. FIS is not responsible for the content or privacy practices of other non-FIS websites to which our websites link. If you are asked to provide information on one of these websites, we encourage you to carefully review their privacy policies before doing so.

TRANSFER OF PERSONAL DATA TO OTHER COUNTRIES

FIS is headquartered in the United States of America, and almost all data we process will be transferred to or accessed from the United States. Our subsidiaries and third-party service providers operate in the European Economic Area (“EEA”), the United Kingdom (“UK”), and multiple other countries around the world.

We may transfer, access, or store personal data about you outside of the EEA, Switzerland, the UK, China, Japan, or another country that requires legal protections for international data transfer. When we do, we will make sure an adequate level of protection is provided for personal data by using one or more of the following approaches:

  • We may transfer personal data to countries that have privacy laws that have been recognized by the country from which the data is transferred as providing similar protections for the data (“adequacy”).
  • We may enter into written agreements, such as standard contractual clauses and other data transfer agreements, with recipients that require them, in substance, to provide the same level of protection for the data.
  • We may seek your consent for transfers of your personal data for specific purposes.
  • We may rely on other transfer mechanisms approved by authorities in the country from which the data is transferred.

FIS:

  • is complying with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce;
  • has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF;
  • has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF.

FIS is committed to the DPF Principles in connection with all personal data received from the European Union and, as applicable, the United Kingdom (and Gibraltar) and/or Switzerland in reliance on the relevant part(s) of the DPF program. If there is any conflict between the terms in this Online Privacy Notice and the DPF Principles, the DPF Principles shall prevail. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

When we share personal data within and among FIS affiliates, we make use of the Standard Contractual Clauses (as approved by the European Commission), the UK International Transfer Addendum, as well as model clauses issued in other countries to legitimize data transfers.

For Japanese individuals, information about the personal information protection system of various foreign countries where your data may be processed is available here. An overview of data protection and privacy legislation worldwide is available here.

MANAGING YOUR PREFERENCES

FIS strives to provide you with choices and preferences regarding certain personal data uses, particularly around marketing and advertising. You may opt-out of receiving communications about FIS products and services by visiting our FIS Subscription Preferences Center at any time.

EXERCISING YOUR RIGHTS

The laws of certain jurisdictions may afford you the right to access your personal data held by FIS and to request correction, amendment, portability, or deletion of your personal data held by FIS. In addition, where applicable, you may have the right to object to processing based on legitimate interests and to withdraw consent where consent forms the legal basis for processing. You have the right not to be subject to decisions based solely on automated processing, including profiling, that have legal or similarly significant effects, and to request human review to express your views and challenge the decision. These rights may be limited, for example, if fulfilling a request would reveal personal data about another person, or if the processing is required by law or another compelling legitimate interest. If you have unresolved concerns, you have the right to complain to a data protection authority. FIS reserves the right, where permitted by law, to verify your identity, and to refuse such requests where appropriate.

For consumers who reside in the State of California, you have the right to opt-out of the disclosure of your personal data for monetary or other valuable consideration.

For individuals in China, you have the right to request that FIS explains the rules set out in this Online Privacy Notice and FIS Privacy Center (Privacy | FIS) (right to explain processing rules). Close relatives of a deceased person have the right to access, make copies of, correct or delete personal data of the deceased person, unless the deceased person has arranged otherwise before their death.

In some circumstances, FIS processes personal data on behalf of its clients and is subject to the control and instructions of its clients. If you believe FIS may have personal data about you due to services FIS provides or has provided to an FIS client with whom you have a relationship, it may not be possible for FIS to respond to your request. In that circumstance, please direct your request to the FIS client with which you have the relationship.

If you want to exercise any of your privacy rights, please complete the form accessible here or contact FIS at:

Chief Privacy Officer
FIS
347 Riverside Avenue
Jacksonville, FL 32202
United States of America
privacyoffice@fisglobal.com

Data Protection Officer
FIS
ul. Sienna 75
5th floor
00-833 Warsaw
Poland
privacyoffice@fisglobal.com

ONLINE PRIVACY NOTICE UPDATES

We keep our Online Privacy Notice under regular review, and, therefore, it is subject to change. Please review this Notice periodically. Any changes will become effective when we post the revised Notice on the site. Your continued use of the site following these changes means that you accept the revised Notice.