How ExactFlow handles payments, protects financial data, and secures transactions on the SaaS Platform
Effective Date: 1 April 2026 | Version 1.0 | Standards: PCI-DSS v4.0; GDPR; PSD2; Polish Payment Services Act
| Document Type | Payment Processing & Security Policy |
| Applies To | All Platform Clients, Sellers, Buyers, and payment transaction participants |
| Payment Contact | billing@exactflow.com |
| Security Contact | security@exactflow.com |
| Fraud Reporting | fraud@exactflow.com |
| Regulatory Framework | PCI-DSS v4.0; EU PSD2 (Directive 2015/2366); Polish Payment Services Act (ustawa o usługach płatniczych); GDPR |
ExactFlow does not store, process, or transmit payment card numbers directly. All card payment processing is performed by ExactFlow's PCI-DSS Level 1 certified payment processing partners. ExactFlow's role in the payment chain is as follows:
| Stage | Actor | ExactFlow's Role | Data Handled by ExactFlow |
|---|---|---|---|
| Payment initiation | Buyer selects payment method at checkout | Presents payment UI; redirects to payment gateway tokenization widget | Order amount, currency, Order reference — no card data |
| Card data capture | Payment gateway (not ExactFlow) | Zero — card data entered directly into the gateway's PCI-DSS compliant widget | None — card data never touches ExactFlow servers |
| Authorisation | Receives authorisation result (approved/declined) | Transaction status, authorisation code, tokenized card reference | |
| Settlement | Receives settlement confirmation | Settlement amount, timestamp, transaction reference | |
| Escrow holding | ExactFlow Escrow (via regulated payment provider) | Manages Escrow period; triggers release after Withdrawal Period | Transaction identifiers, amounts, Seller/Buyer account references |
| Seller Payout | Initiates Payout after Escrow release; deducts Commission | Payout amount, Seller IBAN (encrypted), transaction reference |
| Payment Method | Availability | Processing Standard | Notes |
|---|---|---|---|
| Visa / Mastercard / American Express | All markets | PCI-DSS; 3DS2 authentication required | 3D Secure 2 (Strong Customer Authentication) enforced per PSD2 |
| BLIK (Poland) | Poland | Polish Payment Agent regulation; KNF oversight | Instant payment; no 3DS required — BLIK PIN used |
| Bank Transfer (SEPA) | EU / EEA | SEPA Credit Transfer; SEPA Instant where available | Longer settlement time; used for high-value B2B transactions |
| PayPal | Selected markets | PayPal Merchant Agreement; PCI-DSS | Subject to PayPal's own buyer/seller protection terms |
| Klarna / Buy Now Pay Later | Selected EU markets | PSD2; Consumer Credit Directive | Consumer credit checks conducted by Klarna; B2C Marketplace only |
| Cryptocurrency | Not accepted | N/A | ExactFlow does not accept cryptocurrency payments on any Marketplace |
In compliance with PSD2 Article 97 and the EBA Guidelines on SCA, ExactFlow enforces Strong Customer Authentication for all electronic payment transactions processed on the Platform. SCA requires authentication using at least two independent factors from:
3D Secure 2 (3DS2) is enforced for all card transactions. BLIK authentication satisfies SCA through knowledge (BLIK PIN) and possession (mobile app). Transactions that fail SCA will be declined. Certain SCA exemptions may apply (low-value transactions below €30; merchant-initiated transactions; recurring transactions after SCA on initial setup) — these are managed by our payment processors in compliance with EBA guidelines.
ExactFlow maintains PCI-DSS compliance for its role as a merchant that accepts payment cards. ExactFlow's compliance scope is limited because card data is handled directly by our Level 1-certified payment processors. ExactFlow's specific PCI-DSS obligations include:
Clients who use ExactFlow's Platform to process card payments from their own customers through ExactFlow's payment infrastructure are subject to their own PCI-DSS compliance obligations based on their transaction volume and integration method.
ExactFlow stores only the following payment-related data, and no more:
| Data Element | How Stored | Purpose | Retention |
|---|---|---|---|
| Transaction reference number | Plaintext — non-sensitive identifier | Order management, reconciliation | 7 years (accounting law) |
| Authorisation code | Plaintext — non-sensitive | Transaction verification | 7 years |
| Last 4 digits of card number | Plaintext — non-sensitive per PCI-DSS | Display to user in Account history | 5 years |
| Card expiry month/year | Plaintext — non-sensitive per PCI-DSS | Display to user | 5 years |
| Card brand (Visa, Mastercard etc.) | Plaintext | Display to user | 5 years |
| Payment method token | Encrypted — tokenized reference issued by payment processor | Repeat purchases (with user consent) | Until revoked by user or 3-year inactivity |
| Billing address | Encrypted at rest (AES-256) | Fraud prevention; VAT compliance | 7 years |
| Seller IBAN for Payouts | Encrypted at rest (AES-256); access restricted to Payout processing systems | Seller Payout execution | Duration of Seller relationship + 5 years |
ExactFlow NEVER stores: full primary account numbers (PANs); CVV/CVC/CVC2 security codes; full magnetic stripe data; PIN or PIN block data. Any request to provide such data to ExactFlow or its staff is fraudulent and should be reported immediately to fraud@exactflow.com.
ExactFlow's Escrow service holds Transaction funds between payment and Seller Payout. The Escrow process provides consumer and buyer protection:
| Event | Timeline | Notes |
|---|---|---|
| Order placed | Day 0 | Transaction funds collected from Buyer and held in Escrow |
| Delivery confirmed | Day 0 of confirmation | Withdrawal period begins (B2C: 14 days) |
| Withdrawal period expires (no claim) | Day 14 (B2C) or per contract (B2B) | Escrow release triggered |
| Escrow release to Payout pool | Within 24 hours of release trigger | Commission and fees deducted |
| Payout disbursed to Seller IBAN | Within 7 days of Escrow release | Rolling 7-day Payout cycle |
| Payout statement issued | Same day as disbursement | Itemized via Seller dashboard and email |
The following deductions are made from gross Transaction value before Seller Payout:
ExactFlow may withhold Payouts where: (a) a dispute or withdrawal is pending; (b) a chargeback has been initiated; (c) fraud or AML concerns are under investigation; (d) a court or regulatory order requires withholding. ExactFlow will notify the Seller in writing with reasons within 2 business days of withholding a Payout.
ExactFlow issues VAT-compliant invoices for Platform Fees and Commission in accordance with the Polish VAT Act (ustawa o podatku od towarów i usług) and EU VAT Directive (2006/112/EC). Key invoicing practices:
In the event of a security incident affecting payment data, ExactFlow's Payment Security Incident Response procedure is activated immediately:
Report suspected payment fraud or security incidents to: fraud@exactflow.com or security@exactflow.com. We operate a 24/7 security incident hotline for critical issues: details provided in the Client onboarding pack.
| Billing & Payouts | billing@exactflow.com |
| Payment Security | security@exactflow.com |
| Fraud Reporting | fraud@exactflow.com |
| DPO | privacy@exactflow.com |
| Registered Address | ExactFlow p.s.a., Stanisława Bodycha 87, 05-816 Reguły, Poland |
| Supervisory (Payments) | Komisja Nadzoru Finansowego (KNF) — www.knf.gov.pl |
| Supervisory (Data) | UODO — www.uodo.gov.pl |
This Payment Processing & Security Policy complies with: PCI-DSS v4.0; EU PSD2 (Directive 2015/2366) and EBA SCA Guidelines; Polish Payment Services Act; GDPR; Polish VAT Act; EU VAT Directive (2006/112/EC); and EU Directive 2023/2225 (Consumer Credit, where applicable). Independent review recommended before publication.
— END OF PAYMENT PROCESSING & SECURITY POLICY — EXACTFLOW P.S.A. —