Data Processing Addendum
Cobalt Payments Inc. — gateway.cxbolt.com
Effective Date: July 31, 2026
This Data Processing Addendum ("DPA") is incorporated into and forms part of the Terms of Use between Cobalt Payments Inc. ("Cobalt") and the merchant ("Merchant," "you"). It governs Cobalt's processing of Merchant Personal Information. In the event of conflict between this DPA and the Terms of Use as to the processing of Merchant Personal Information, this DPA controls.
1. Definitions
- Applicable Data Protection Law — U.S. federal and state privacy and data-security laws applicable to the parties, including the Gramm-Leach-Bliley Act ("GLBA") and Regulation P, the GLBA Safeguards Rule, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the comprehensive privacy statutes of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states as they take effect.
- Merchant Personal Information — personal information relating to Merchant's customers, cardholders, and end users that Cobalt processes on Merchant's behalf in providing the Services.
- Business / Controller, Service Provider / Processor, Consumer, Sell, Share, Sensitive Personal Information — as defined in the CCPA/CPRA and comparable statutes.
- Sub-Processor — a third party engaged by Cobalt to process Merchant Personal Information.
- Security Incident — a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Merchant Personal Information.
Scope note. This DPA addresses U.S. law. The Services are not offered for the processing of personal data subject to the EU GDPR or UK GDPR, and this DPA does not include standard contractual clauses. See Privacy Policy Section 19.
2. Roles of the Parties
2.1 With respect to Merchant Personal Information, Merchant is the Business / Controller and Cobalt is the Service Provider / Processor.
2.2 With respect to information about Merchant itself and its personnel — account, underwriting, KYC, risk, billing, and support data — Cobalt is the Business / Controller and processes it under the Privacy Policy, not this DPA.
2.3 Cobalt also processes certain data as required by law, the Card-Network Rules, and its own regulatory obligations — including anti-money-laundering, sanctions screening, fraud prevention, risk management, and audit. In performing those functions Cobalt acts on its own behalf and as a Business / Controller, as permitted by the CCPA/CPRA and comparable statutes, and not as Merchant's Service Provider.
3. Cobalt's Obligations as Service Provider
Cobalt will:
3.1 Purpose limitation. Process Merchant Personal Information only (a) to provide, secure, support, and maintain the Services under the Terms of Use, (b) on Merchant's documented instructions, and (c) as otherwise permitted or required by Applicable Data Protection Law.
3.2 Statutory restrictions. Cobalt will not:
- Sell or Share Merchant Personal Information;
- Retain, use, or disclose it for any purpose other than the business purposes specified in this DPA, including any commercial purpose of its own, except as Section 3.3 permits;
- Retain, use, or disclose it outside the direct business relationship with Merchant;
- Combine it with personal information received from another source, except as permitted by the CCPA/CPRA to perform a business purpose, to detect security incidents, or to prevent fraud; or
- Use it to build or improve profiles for cross-context behavioral advertising.
3.3 Permitted internal uses. Cobalt may use Merchant Personal Information to detect and prevent fraud and security incidents; to debug and repair errors; to comply with law and the Card-Network Rules; to enforce its agreements and protect legal rights; for internal use to build, improve, and maintain the quality of the Services; and to create aggregated and de-identified information as permitted by Section 8.
3.4 De-identification. Where Cobalt creates de-identified or aggregated information, it will implement reasonable measures to prevent re-identification, publicly commit not to attempt re-identification, and contractually obligate recipients to the same. Cobalt will not attempt to re-identify de-identified information.
3.5 Notice of inability to comply. Cobalt will notify Merchant if it determines it can no longer meet its obligations under Applicable Data Protection Law.
3.6 Compliance. Cobalt will comply with its obligations under Applicable Data Protection Law and will provide the same level of privacy protection as required of Merchant with respect to Merchant Personal Information.
4. Merchant's Obligations
Merchant will:
4.1 Lawful basis and notices. Provide its end users with all privacy notices and information required by law, make any necessary choices available, and obtain any consents necessary to enable both parties to comply with Applicable Data Protection Law — including notice of how and why personal and financial information is collected, used, and disclosed.
4.2 Own privacy policy. Maintain and publish an accurate privacy policy covering its collection and use of customer data and its use of the Services. Cobalt does not provide, review, or approve Merchant's privacy policy, and is not responsible for Merchant's privacy practices.
4.3 Data minimization and accuracy. Ensure that Merchant Personal Information it submits is adequate, relevant, and limited to what is necessary for the processing contemplated, and is accurate and, where necessary, kept up to date.
4.4 Lawful instructions. Give only instructions that comply with Applicable Data Protection Law. Merchant is solely responsible for the lawfulness of its instructions and of its collection of the data it submits.
4.5 Prohibited data. Not submit (a) sensitive authentication data after authorization, (b) cardholder data in free-text fields, or (c) special-category data — health, biometric, genetic, precise geolocation, or government-ID images — except where a feature expressly requires it.
4.6 Consumer requests. Be responsible for receiving, verifying, and responding to consumer rights requests concerning Merchant Personal Information. Cobalt will refer any request it receives directly to Merchant.
4.7 Communications consent. Hold all consents required for email and SMS sent through the Services, per Terms of Use Section 12.
5. Assistance with Consumer Rights
On Merchant's written request, and to the extent Merchant cannot reasonably do so through the Portal's self-service features, Cobalt will provide commercially reasonable assistance in responding to verified consumer requests to access, delete, correct, or port Merchant Personal Information. Cobalt may charge for assistance that is excessive, repetitive, or requires non-standard engineering effort. Cobalt will not delete data it is required to retain by law, the Card-Network Rules, a legal hold, or for fraud prevention, security, or its own regulatory obligations, and will inform Merchant where a request cannot be fully honored for that reason.
6. Security
6.1 Cobalt will implement and maintain appropriate administrative, technical, physical, and organizational safeguards designed to protect Merchant Personal Information against a Security Incident, consistent with the GLBA Safeguards Rule and applicable PCI DSS requirements, including the measures described in Privacy Policy Section 13.
6.2 Personnel. Cobalt will limit access to personnel with a need to know, bind them to confidentiality, and provide security and privacy training.
6.3 Merchant-side security. Merchant is solely responsible for the security of data residing on any server, device, terminal, or environment owned or operated by Merchant or any third party Merchant designates, and for its own access controls, user provisioning, and credential hygiene. See Terms of Use Section 11 and the PCI DSS Responsibility Matrix.
7. Sub-Processors
7.1 Authorization. Merchant grants general written authorization for Cobalt to engage Sub-Processors to process Merchant Personal Information.
7.2 Flow-down. Cobalt will impose on each Sub-Processor written obligations materially no less protective than this DPA, and will remain responsible for its Sub-Processors' performance of those obligations.
7.3 List and changes. The current Sub-Processor List is maintained at the location stated in the Sub-Processor List document. Cobalt will provide a mechanism for Merchant to be notified of a new Sub-Processor. If Merchant reasonably objects on documented data-protection grounds within fifteen (15) days, the parties will discuss in good faith; if no resolution is reached, Merchant's exclusive remedy is to terminate the affected Services.
7.4 Transaction chain. Merchant acknowledges that the card networks, debit networks, issuers, acquirers, and sponsor bank are independent controllers in the payment transaction chain — not Cobalt's Sub-Processors — and process data under their own rules and obligations. See Privacy Policy Section 6.
8. Aggregated and De-Identified Data
Cobalt may create and use aggregated, statistical, and de-identified information derived from Merchant's use of the Services for any lawful purpose, including improving the Services, security and fraud research, and publishing benchmarks. Such information will not identify Merchant, any consumer, or any individual. This Section survives termination.
9. Security Incident Response
9.1 Cobalt will notify Merchant without undue delay after becoming aware of a Security Incident affecting Merchant Personal Information, and in any event within the period required by Applicable Data Protection Law.
9.2 The notice will include, to the extent known and as it becomes available: the nature and timing of the incident, the categories and approximate volume of data affected, likely consequences, and measures taken or proposed.
9.3 Cobalt will take reasonable steps to contain and remediate, and will provide information reasonably necessary for Merchant to meet its own notification obligations.
9.4 Merchant is responsible for determining whether notification to consumers, regulators, or card networks is required for incidents involving data it controls, and for making those notifications. Cobalt's notice is not an admission of fault or liability.
9.5 Merchant will notify security@cxbolt.com within twenty-four (24) hours of discovering any actual or suspected compromise involving cardholder or personal data in its environment, per Terms of Use Section 11.5.
10. Audit and Documentation
Cobalt will, on reasonable written request no more than once per twelve (12) months (unless required by a regulator or following a Security Incident), make available a summary of its then-current security posture and the PCI DSS validation status of the underlying gateway and processor, subject to confidentiality. Because card data is captured directly by NMI and does not transit Cobalt-controlled servers, Cobalt’s environment is not a cardholder data environment and Cobalt does not hold a separate Attestation of Compliance. Cobalt is not obligated to permit on-site inspection of its facilities or to disclose information that would compromise the security of Cobalt or its other customers.
11. Retention and Deletion
Cobalt will retain Merchant Personal Information as described in Privacy Policy Section 12. On termination, Cobalt will delete or de-identify Merchant Personal Information within a commercially reasonable period except where retention is required by law, the Card-Network Rules, a legal hold, or for fraud prevention, dispute resolution, or Cobalt's own regulatory obligations. Merchant should export its data before terminating — see Terms of Use Section 23.4.
12. Liability and Term
12.1 Each party's liability under this DPA is subject to the exclusions and limitations in Terms of Use Section 20, including the aggregate cap and its carve-outs.
12.2 This DPA takes effect when Merchant accepts the Terms of Use and continues until Cobalt ceases processing Merchant Personal Information. Sections 3.4, 8, 11, and 12 survive.
13. Contact
Privacy Office, Cobalt Payments Inc., 2264 Silas Deane Hwy, Suite 105, Rocky Hill, CT 06067 — privacy@cxbolt.com. Security incidents — security@cxbolt.com.
© 2026 Cobalt Payments Inc. All rights reserved. Cobalt Payments Inc. is a registered ISO of Wells Fargo Bank, N.A., Concord, CA. The Clover trademark logo is owned by Clover Network, Inc., a First Data company. All other trademarks, service marks and trade names referenced in this material are the property of their respective owners.